During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct find /usr -perm 4000

Wrong. Without a leading - or /, -perm requires the mode to match exactly. This finds only files whose permissions are precisely 4000 (---S------), so an ordinary setuid binary at 4755 is missed.

Not correct find /usr -perm -755

Wrong. This matches files that have at least rwxr-xr-x. It says nothing about the setuid bit, and it will match huge numbers of ordinary executables.

Correct find /usr -perm -4000

Correct. A leading minus means 'all of these bits are set, others do not matter', so 4755, 4711 and 4111 all match. `find /usr -perm -u+s` is the symbolic equivalent.

Not correct find /usr -type s

Wrong. -type selects a file type, and type s is a Unix domain socket. The setuid bit is a permission bit, not a file type.

Why

find's -perm test has three forms. A bare mode (-perm 4000) is an exact match on all twelve permission bits. A leading minus (-perm -4000) means every listed bit must be set and extra bits are ignored, which is the form you want when hunting setuid files. A leading slash (-perm /4000) means at least one of the listed bits is set, which is useful for -perm /6000 to catch setuid or setgid in one pass. Symbolic forms work too: -perm -u+s for setuid, -perm -g+s for setgid.

Where this comes from

Cited
LPI exam objective 110.1
What it says
Locate files with the setuid and setgid bits set as part of routine security auditing.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500