CompTIA Linux+ (XK0-006)System ManagementHard

A security policy requires that the /tmp partition on a server be mounted so that no binaries can be executed from it, the setuid/setgid bits have no effect, and no device files can be created or accessed there. Which comma-separated options should the technician add to the /tmp entry in /etc/fstab?

  1. Aro,noauto,user
  2. Bnoexec,ro,sync
  3. Cexec,suid,dev
  4. Dnoexec,nosuid,nodev
Show answer & explanation

Correct answer: D. noexec,nosuid,nodev

The 'noexec' option prevents execution of binaries, 'nosuid' disables the effect of setuid/setgid bits, and 'nodev' prevents device files from being interpreted as such on that filesystem — together they satisfy all three requirements. The other option sets are missing one or more of these security controls or add unrelated behaviors.

Why the other options are wrong

  • A. Makes the filesystem read-only and requires manual mounting but does not address execution or device restrictions.
  • B. Blocks execution and forces read-only, but does not disable setuid or device file behavior.
  • C. Explicitly enables execution, setuid effect, and device files — the opposite of the requirement.

noexec,nosuid,nodev

A common fstab hardening option set that disables binary execution, setuid/setgid privilege escalation, and device file access on a mount point.

  • Frequently applied to /tmp and other writable partitions
  • noexec blocks running programs from that filesystem
  • nosuid ignores setuid/setgid bits; nodev ignores device special files

Memory trick: Lock /tmp down: no run, no super-power, no devices.

More System Management questions