Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?

⚠ Common exam trap

Test-takers frequently confuse a global runtime mode change with per-domain permissive settings or boolean toggles, which affect only specific policy components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

setenforce 0

The setenforce command changes the SELinux mode at runtime. Passing 0 selects permissive mode, where denials are logged but not enforced. This satisfies the requirement to switch temporarily without rebooting. Persistent changes require editing /etc/selinux/config, but the scenario explicitly asks for a runtime change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    setenforce 0

    Why this is correct

    setenforce 0 switches SELinux from enforcing to permissive mode immediately in the running kernel. In permissive mode, policy violations are logged but not blocked, which is exactly the temporary change requested. The command takes effect without a reboot and does not alter the persistent configuration in /etc/selinux/config.

  • ✗

    setsebool -P httpd_can_network_connect on

    Why it's wrong here

    setsebool toggles a specific SELinux boolean and the -P flag makes it persistent across reboots. This changes policy behavior for one feature, not the global SELinux mode. It does not set the system to permissive, so it cannot fulfill the administrator's goal of temporarily disabling enforcement for all domains.

  • ✗

    semanage permissive -a httpd_t

    Why it's wrong here

    semanage permissive -a adds a domain to the permissive domains list, causing only that domain to run without enforcement while the rest of the system remains enforcing. This is a targeted change, not a global mode switch. The administrator asked to set the SELinux mode to permissive, which affects all domains, so this command is too narrow.

  • ✗

    restorecon -R /

    Why it's wrong here

    restorecon relabels files to match the SELinux policy context and does not change the SELinux mode. Running it recursively on the root filesystem could be disruptive and would not make the system permissive. It addresses file context mismatches, not global enforcement behavior, so it fails the stated objective.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.