Courseiva
Configure local storage →hardMultiple Choice

EX200 Configure local storage Practice Question

Exhibit

# mount | grep /dev/mapper
/dev/mapper/data-lv on /data type xfs (rw,noexec,relatime,seclabel,attr2,inode64,noquota)

Refer to the exhibit. A user tries to execute a script located in /data/script.sh but gets 'Permission denied'. The script has execute permissions. What is the most likely cause?

⚠ Common exam trap

Red Hat often tests the distinction between file-level permissions and filesystem-level mount options, where candidates mistakenly think execute permissions alone guarantee execution, ignoring that mount options like 'noexec' can override them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The filesystem is mounted with noexec

The most likely cause is that the filesystem where /data resides is mounted with the 'noexec' option. This mount option prevents the execution of any binary or script directly from that filesystem, regardless of the file's individual execute permissions. The 'noexec' flag is commonly set on partitions like /tmp or /var for security reasons, and it overrides the file's permission bits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The filesystem is mounted with noexec

    Why this is correct

    A `noexec` mount option on the filesystem is the direct cause: the kernel refuses to execute any file (binary or script) from that mount, even if the file has executable permissions set. This is enforced at the VFS layer, so attempting to run the script with `./script.sh` will return `Permission denied` or `Operation not permitted`, matching the reported symptom. The option is set in `/etc/fstab` (or via `mount -o noexec`), and it overrides normal execute-bit checks.

  • ✗

    The filesystem is full

    Why it's wrong here

    A full filesystem would not prevent script execution; it would instead produce errors when the script tries to write output, create temporary files, or when the shell needs to create history files or PID files. Executing a read-only script requires no free space, so a full disk would typically manifest as `No space left on device` during write operations, not as a generic `Permission denied` on execution. Furthermore, the system would likely show broader warning messages, such as in `df -h` output.

  • ✗

    SELinux is blocking execution

    Why it's wrong here

    SELinux denials do produce `Permission denied`, but they are accompanied by specific AVC denial messages logged to `/var/log/audit/audit.log` (or `journalctl` if auditd is not running). A deny due to SELinux would be based on file context and process domain, not on the mount options, and would be resolvable with `restorecon`, `chcon`, or a boolean change. Without any SELinux alert or `ausearch -m AVC` findings, this is not the cause; the error would be identical even after temporarily setting SELinux to permissive mode.

  • ✗

    The script is in a directory with noexec

    Why it's wrong here

    The `noexec` attribute is a mount option only; there is no standard per-directory `noexec` attribute. While individual directories can have `setgid`, `sticky`, or ACL attributes, execute prevention on a directory is simply the lack of `x` permission for relevant users. If the directory lacked execute permission, the user could not `cd` into it or traverse it, which would produce a different error than a `noexec` mount. The script's directory cannot independently disable execution; only the underlying filesystem mount can, making this option a category error.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.