| For systems that use UEFI, this is Not Applicable. |
Verify the /boot directory is mounted with the "nosuid" option with the following command:
$ sudo mount | grep '\s/boot\s'
/dev/sda1 on /boot type xfs (rw,nosuid,relatime,seclabe,attr2,inode64,noquota)
If the /boot file system does not have the "nosuid" option set, this is a finding.