Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?

⚠ Common exam trap

Watch out — candidates often confuse `ausearch` with `aureport` or `auditctl`, or think `restorecon` can fix AVC denials, when in fact only `ausearch` paired with `audit2allow` provides the complete solution for generating a custom policy from a denial message.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ausearch and audit2allow

`ausearch` retrieves the full AVC denial message from the audit log, and `audit2allow` generates a policy module to allow the denied access. Together, they enable the administrator to first identify the exact denial and then create a custom SELinux policy to permit the httpd_t domain's blocked action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    auditctl and ausearch

    Why it's wrong here

    auditctl sets kernel audit rules and ausearch queries existing records, but neither translates an AVC denial into a loadable policy module. That is the job of audit2allow, which reads ausearch output and emits a .te rule set. auditctl and ausearch suit live rule tuning and log review, not policy generation.

  • ✗

    ausearch and restorecon

    Why it's wrong here

    restorecon resets SELinux file contexts; it neither displays the full AVC denial nor generates an allow policy. It is tempting because mislabelled contexts cause denials, and would be correct if the audit showed a wrong file type rather than a policy gap.

  • ✗

    aureport and audit2why

    Why it's wrong here

    aureport summarises audit events into counts and reports, discarding the raw denial detail needed to build a policy, and audit2why only explains a denial rather than emitting allow rules. Reporting is tempting for spotting denial trends, but policy generation requires ausearch piped into audit2allow.

  • ✓

    ausearch and audit2allow

    Why this is correct

    ausearch retrieves the full AVC denial records from the audit log, while audit2allow converts those denials into allow rules for a loadable policy module. Together they reveal the complete denial and generate the targeted SELinux policy.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.