Security & Restriction Mount Options Flashcards

(14 cards)

1
Q

What do Linux security mount options do?

A

Enhance security by restricting filesystem behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name common security mount options.

A

nodev, nosuid, noexec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does nodev do?

A

Prevents special device files on a filesystem from being treated as actual devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why use nodev?

A

Prevents unauthorized access to hardware or system functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Syntax for nodev?

A

mount -o nodev <device> <mountpoint></mountpoint></device>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Example of nodev?

A

sudo mount -o nodev /dev/sdb1 /mnt/safe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does nosuid do?

A

Prevents execution of files with SUID or SGID bits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why use nosuid?

A

Blocks files from gaining elevated privileges when run

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Syntax for nosuid?

A

mount -o nosuid <device> <mountpoint></mountpoint></device>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Example of nosuid?

A

sudo mount -o nosuid /dev/sdb1 /mnt/no-suid

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does noexec do?

A

Prevents execution of any binaries or scripts located on the filesystem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why use noexec?

A

Protects against unauthorized or malicious code execution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Syntax for noexec?

A

mount -o noexec <device> <mountpoint></mountpoint></device>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Example of noexec?

A

sudo mount -o noexec /dev/sdb1 /mnt/lockdown

How well did you know this?
1
Not at all
2
3
4
5
Perfectly