RHCSA SELinux Contexts and Booleans Flashcards
7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 RHCSA SELinux Contexts and Booleans flashcards as text
A service fails and audit.log shows 'type=AVC msg=audit: denied { name_connect } for pid=1234 comm="httpd"'. What does 'name_connect' indicate?
Answer: Apache attempted an outbound TCP connection to a remote port
name_connect is the SELinux permission checked when a process initiates an outbound TCP connection to a specific port number.
Which command would you use to add port 8888 to the http_port_t SELinux type so Apache can listen on it?
Answer: semanage port -a -t http_port_t -p tcp 8888
semanage port -a adds a port-to-type mapping; without it, Apache is denied the bind permission on non-standard ports.
What does 'semanage permissive -a httpd_t' do?
Answer: Puts only the httpd_t domain into permissive mode while the rest of the system remains enforcing
Per-domain permissive mode lets a single type run unrestricted and log denials without affecting the enforcement of other domains.
The command 'ls -Z /var/www/html/app.php' shows 'user_home_t'. What is the quickest correct fix?
Answer: restorecon /var/www/html/app.php
restorecon resets the file to the context already defined for /var/www/html in the policy database, which is httpd_sys_content_t.
Which tool generates a loadable SELinux policy module (.pp file) from AVC denial messages?
Answer: audit2allow -M mymodule
audit2allow -M reads AVC denials, generates a .te source and compiles it into a loadable .pp module in one step.
After loading a custom SELinux module with 'semodule -i custom.pp', how do you verify it is loaded?
Answer: semodule -l | grep custom
semodule -l lists all installed policy modules; grep filters for the specific module name.
Which boolean enables NFS home directories to work correctly with SELinux for user logins?
Answer: use_nfs_home_dirs
use_nfs_home_dirs allows confined user domains to access home directories mounted via NFS.