โ† All RHCSA Flashcard Decks

RHCSA SELinux Contexts and Booleans Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA SELinux Contexts and Booleans flashcards as text
  1. A script running as cron_t needs to write to /var/log/myapp.log. The file has type var_log_t. What should you do to allow this properly?

    Answer: Use audit2allow to create a module allowing cron_t write to var_log_t

    When no standard boolean covers the case, audit2allow creates a minimal targeted policy allowing the specific cron_t write to var_log_t.

  2. Which SELinux user is typically mapped to the Linux root account in the targeted policy?

    Answer: unconfined_u

    In the targeted policy, root logs in as unconfined_u, giving it the unconfined_t domain and effectively unrestricted access.

  3. You copy /etc/passwd to /srv/myapp/passwd. What SELinux context will the copy have by default?

    Answer: The context matching the destination directory: var_t or srv_t

    cp inherits the destination directory's context for new files unless --preserve=context is specified.

  4. Which command shows the SELinux context of a running process?

    Answer: ps auxZ | grep httpd

    ps auxZ adds a column showing the SELinux security context (domain) of each running process.

  5. What is the purpose of the 'object_r' role seen in file SELinux contexts like 'system_u:object_r:httpd_sys_content_t:s0'?

    Answer: It is a placeholder role used for filesystem objects since roles apply only to subjects

    Roles are meaningful only for subjects (processes); object_r is the conventional placeholder role for all filesystem objects.

  6. An administrator sets 'setsebool -P httpd_execmem on'. What risk does this boolean introduce?

    Answer: It permits Apache to allocate memory that is both writable and executable, increasing the attack surface

    httpd_execmem allows the httpd domain to use execmem, which enables write-then-execute memory patterns exploited by shellcode injection.

  7. Which command removes a custom semanage fcontext rule that was previously added for /opt/myapp(/.*)?

    Answer: semanage fcontext -d '/opt/myapp(/.*)?'

    semanage fcontext -d deletes a previously added file context rule from the persistent policy database.