RHCSA File Permissions and ACLs Flashcards
7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 RHCSA File Permissions and ACLs flashcards as text
Which file stores the default umask for all users logging in via a shell on a RHEL system?
Answer: /etc/profile
/etc/profile sets system-wide environment defaults including umask for login shells.
A directory listing shows 'drwxrwt---'. What special bit is set?
Answer: Sticky bit
A lowercase 't' in the other-execute position indicates the sticky bit is set and execute is also enabled.
User tom wants to allow user sara read and execute access to /opt/app without changing the file's group. What is the best approach?
Answer: setfacl -m u:sara:rx /opt/app
ACLs allow granting per-user permissions without modifying group ownership or broad 'other' permissions.
What does 'setfacl -R -m u:bob:rwx /shared' do?
Answer: Recursively adds an ACL granting bob full access to all files under /shared
The -R flag makes setfacl apply the ACL modification recursively to all files and subdirectories.
Which command would verify that an ACL is effectively limiting group 'interns' to read-only despite a broader ACL entry?
Answer: getfacl file and check the effective: comment next to the group entry
getfacl displays 'effective:' annotations showing the ACL mask's impact on each entry's actual permissions.
A script /usr/local/bin/backup.sh is owned by root with permissions rwsr-xr-x. What security concern does this raise?
Answer: Any user who executes the script will run it as root, creating a privilege escalation risk
setuid on a root-owned script means all users execute it with root privileges, which is a significant attack surface.
Which command backs up all ACLs from the /project directory tree into a file for later restoration?
Answer: getfacl -R /project > acl_backup.txt
getfacl -R outputs all ACL entries recursively in a format that setfacl --restore can later reimport.