Verify "/home" is mounted with the "nosuid" option with the following command:
Note: If a separate file system has not been created for the user home directories (user home directories are mounted under "/"), this is automatically a finding, as the "nosuid" option cannot be used on the "/" system.
$ mount | grep /home
/dev/mapper/luks-10a20c46-483d-4d12-831f-5328eda18fd1 on /home type xfs (rw,nosuid,nodev,relatime,seclabel,attr2,inode64,logbufs=8,logbsize=32k,noquota)
If the "/home" file system is mounted without the "nosuid" option, this is a finding.
Fix
Modify "/etc/fstab" to use the "nosuid" option on the "/home" directory.