โ† All RHCSA Flashcard Decks

RHCSA File Permissions and ACLs Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA File Permissions and ACLs flashcards as text
  1. Which file stores the default umask for all users logging in via a shell on a RHEL system?

    Answer: /etc/profile

    /etc/profile sets system-wide environment defaults including umask for login shells.

  2. A directory listing shows 'drwxrwt---'. What special bit is set?

    Answer: Sticky bit

    A lowercase 't' in the other-execute position indicates the sticky bit is set and execute is also enabled.

  3. User tom wants to allow user sara read and execute access to /opt/app without changing the file's group. What is the best approach?

    Answer: setfacl -m u:sara:rx /opt/app

    ACLs allow granting per-user permissions without modifying group ownership or broad 'other' permissions.

  4. What does 'setfacl -R -m u:bob:rwx /shared' do?

    Answer: Recursively adds an ACL granting bob full access to all files under /shared

    The -R flag makes setfacl apply the ACL modification recursively to all files and subdirectories.

  5. Which command would verify that an ACL is effectively limiting group 'interns' to read-only despite a broader ACL entry?

    Answer: getfacl file and check the effective: comment next to the group entry

    getfacl displays 'effective:' annotations showing the ACL mask's impact on each entry's actual permissions.

  6. A script /usr/local/bin/backup.sh is owned by root with permissions rwsr-xr-x. What security concern does this raise?

    Answer: Any user who executes the script will run it as root, creating a privilege escalation risk

    setuid on a root-owned script means all users execute it with root privileges, which is a significant attack surface.

  7. Which command backs up all ACLs from the /project directory tree into a file for later restoration?

    Answer: getfacl -R /project > acl_backup.txt

    getfacl -R outputs all ACL entries recursively in a format that setfacl --restore can later reimport.