RHCSA SELinux Contexts and Booleans Flashcards
7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 RHCSA SELinux Contexts and Booleans flashcards as text
A script running as cron_t needs to write to /var/log/myapp.log. The file has type var_log_t. What should you do to allow this properly?
Answer: Use audit2allow to create a module allowing cron_t write to var_log_t
When no standard boolean covers the case, audit2allow creates a minimal targeted policy allowing the specific cron_t write to var_log_t.
Which SELinux user is typically mapped to the Linux root account in the targeted policy?
Answer: unconfined_u
In the targeted policy, root logs in as unconfined_u, giving it the unconfined_t domain and effectively unrestricted access.
You copy /etc/passwd to /srv/myapp/passwd. What SELinux context will the copy have by default?
Answer: The context matching the destination directory: var_t or srv_t
cp inherits the destination directory's context for new files unless --preserve=context is specified.
Which command shows the SELinux context of a running process?
Answer: ps auxZ | grep httpd
ps auxZ adds a column showing the SELinux security context (domain) of each running process.
What is the purpose of the 'object_r' role seen in file SELinux contexts like 'system_u:object_r:httpd_sys_content_t:s0'?
Answer: It is a placeholder role used for filesystem objects since roles apply only to subjects
Roles are meaningful only for subjects (processes); object_r is the conventional placeholder role for all filesystem objects.
An administrator sets 'setsebool -P httpd_execmem on'. What risk does this boolean introduce?
Answer: It permits Apache to allocate memory that is both writable and executable, increasing the attack surface
httpd_execmem allows the httpd domain to use execmem, which enables write-then-execute memory patterns exploited by shellcode injection.
Which command removes a custom semanage fcontext rule that was previously added for /opt/myapp(/.*)?
Answer: semanage fcontext -d '/opt/myapp(/.*)?'
semanage fcontext -d deletes a previously added file context rule from the persistent policy database.