โ† All RHCSA Flashcard Decks

RHCSA SELinux Contexts and Booleans Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA SELinux Contexts and Booleans flashcards as text
  1. An SELinux denial appears in /var/log/audit/audit.log. Which tool converts that denial into a human-readable explanation with suggested fixes?

    Answer: sealert -a /var/log/audit/audit.log

    sealert analyzes audit log AVC messages and provides plain-English explanations and prioritized remediation steps.

  2. What does the SELinux type 'httpd_sys_rw_content_t' allow that 'httpd_sys_content_t' does not?

    Answer: Apache to both read and write the file

    httpd_sys_rw_content_t grants the httpd domain read and write access, while httpd_sys_content_t grants read-only access.

  3. Which file stores the mapping of file paths to SELinux contexts used by restorecon?

    Answer: /etc/selinux/targeted/contexts/files/file_contexts

    The file_contexts file under the policy directory contains all path-to-context mappings that restorecon and matchpathcon reference.

  4. Which command temporarily sets a single process's SELinux domain for troubleshooting without modifying policy?

    Answer: runcon -t vsftpd_t -- /usr/sbin/vsftpd

    runcon executes a command in a specified security context, useful for testing without policy changes.

  5. You want to allow Samba to share home directories. Which boolean must be enabled?

    Answer: samba_enable_home_dirs

    samba_enable_home_dirs allows the Samba daemon to read and share user home directories under SELinux.

  6. After enabling the boolean 'httpd_can_sendmail', what additional step is required to make the change survive a reboot?

    Answer: No additional step; setsebool -P already persists the change

    The -P flag to setsebool writes the boolean to persistent storage, making it survive reboots without any additional command.

  7. Which SELinux context label component identifies the sensitivity level in MLS/MCS policies?

    Answer: Level (e.g., s0:c0,c1)

    The level field (format s:c) encodes MLS sensitivity and MCS category information.