XK0-006 Security Practice Question
A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?
⚠ Common exam trap
It's easy for candidates to confuse semanage port -a with -m; the -m option is for modifying an existing port assignment, not for adding a new one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
semanage port -a -t http_port_t -p tcp 8080
To allow httpd to listen on TCP port 8080 in enforcing mode, the port must be added to the http_port_t SELinux type using semanage port -a. This is persistent and does not require disabling SELinux. Modifying an existing port definition is only for reassigning a port that is already defined, and boolean or file context changes do not affect port bindings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
semanage port -a -t http_port_t -p tcp 8080
Why this is correct
This command uses semanage to add TCP port 8080 to the http_port_t type, which is the SELinux type that httpd is allowed to bind to. The -a flag adds a new port definition, -t specifies the type, and -p specifies the protocol. This change is persistent across reboots and allows httpd to listen on port 8080 without disabling SELinux.
- ✗
semanage port -m -t http_port_t -p tcp 8080
Why it's wrong here
The -m option modifies an existing port definition. Since port 8080 is not already assigned to http_port_t, the modify operation will fail because there is no existing entry to change. To add a new port, the -a option must be used. This command would only work if the port was already defined and needed to be reassigned.
- ✗
chcon -t http_port_t /etc/httpd/conf/httpd.conf
Why it's wrong here
chcon changes the SELinux context of a file, not of a network port. Applying this to the httpd configuration file would alter its file type, potentially causing access issues, but would not affect the port binding permission. Ports are managed with semanage port, not with file context commands.
- ✗
setsebool -P httpd_can_network_connect 1
Why it's wrong here
This boolean allows httpd to make outbound network connections, not to bind to a specific port. It controls whether the web server can connect to remote services, which is unrelated to the local listening port. Using this boolean would not permit httpd to bind to port 8080 and would unnecessarily broaden the SELinux policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.