โ† All RHCSA Flashcard Decks

RHCSA SELinux Contexts and Booleans Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA SELinux Contexts and Booleans flashcards as text
  1. A service fails and audit.log shows 'type=AVC msg=audit: denied { name_connect } for pid=1234 comm="httpd"'. What does 'name_connect' indicate?

    Answer: Apache attempted an outbound TCP connection to a remote port

    name_connect is the SELinux permission checked when a process initiates an outbound TCP connection to a specific port number.

  2. Which command would you use to add port 8888 to the http_port_t SELinux type so Apache can listen on it?

    Answer: semanage port -a -t http_port_t -p tcp 8888

    semanage port -a adds a port-to-type mapping; without it, Apache is denied the bind permission on non-standard ports.

  3. What does 'semanage permissive -a httpd_t' do?

    Answer: Puts only the httpd_t domain into permissive mode while the rest of the system remains enforcing

    Per-domain permissive mode lets a single type run unrestricted and log denials without affecting the enforcement of other domains.

  4. The command 'ls -Z /var/www/html/app.php' shows 'user_home_t'. What is the quickest correct fix?

    Answer: restorecon /var/www/html/app.php

    restorecon resets the file to the context already defined for /var/www/html in the policy database, which is httpd_sys_content_t.

  5. Which tool generates a loadable SELinux policy module (.pp file) from AVC denial messages?

    Answer: audit2allow -M mymodule

    audit2allow -M reads AVC denials, generates a .te source and compiles it into a loadable .pp module in one step.

  6. After loading a custom SELinux module with 'semodule -i custom.pp', how do you verify it is loaded?

    Answer: semodule -l | grep custom

    semodule -l lists all installed policy modules; grep filters for the specific module name.

  7. Which boolean enables NFS home directories to work correctly with SELinux for user logins?

    Answer: use_nfs_home_dirs

    use_nfs_home_dirs allows confined user domains to access home directories mounted via NFS.