CompTIA Linux+ (XK0-006)System ManagementHard
A security policy requires that the /tmp partition on a server be mounted so that no binaries can be executed from it, the setuid/setgid bits have no effect, and no device files can be created or accessed there. Which comma-separated options should the technician add to the /tmp entry in /etc/fstab?
- Aro,noauto,user
- Bnoexec,ro,sync
- Cexec,suid,dev
- Dnoexec,nosuid,nodev
Show answer & explanationAnswer & explanation
Correct answer: D. noexec,nosuid,nodev
The 'noexec' option prevents execution of binaries, 'nosuid' disables the effect of setuid/setgid bits, and 'nodev' prevents device files from being interpreted as such on that filesystem — together they satisfy all three requirements. The other option sets are missing one or more of these security controls or add unrelated behaviors.
Why the other options are wrong
- A. Makes the filesystem read-only and requires manual mounting but does not address execution or device restrictions.
- B. Blocks execution and forces read-only, but does not disable setuid or device file behavior.
- C. Explicitly enables execution, setuid effect, and device files — the opposite of the requirement.
noexec,nosuid,nodev
A common fstab hardening option set that disables binary execution, setuid/setgid privilege escalation, and device file access on a mount point.
- Frequently applied to /tmp and other writable partitions
- noexec blocks running programs from that filesystem
- nosuid ignores setuid/setgid bits; nodev ignores device special files
Memory trick: Lock /tmp down: no run, no super-power, no devices.