XK0-006 Security Practice Question
A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?
⚠ Common exam trap
Test-takers frequently confuse a global runtime mode change with per-domain permissive settings or boolean toggles, which affect only specific policy components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
setenforce 0
The setenforce command changes the SELinux mode at runtime. Passing 0 selects permissive mode, where denials are logged but not enforced. This satisfies the requirement to switch temporarily without rebooting. Persistent changes require editing /etc/selinux/config, but the scenario explicitly asks for a runtime change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
setenforce 0
Why this is correct
setenforce 0 switches SELinux from enforcing to permissive mode immediately in the running kernel. In permissive mode, policy violations are logged but not blocked, which is exactly the temporary change requested. The command takes effect without a reboot and does not alter the persistent configuration in /etc/selinux/config.
- ✗
setsebool -P httpd_can_network_connect on
Why it's wrong here
setsebool toggles a specific SELinux boolean and the -P flag makes it persistent across reboots. This changes policy behavior for one feature, not the global SELinux mode. It does not set the system to permissive, so it cannot fulfill the administrator's goal of temporarily disabling enforcement for all domains.
- ✗
semanage permissive -a httpd_t
Why it's wrong here
semanage permissive -a adds a domain to the permissive domains list, causing only that domain to run without enforcement while the rest of the system remains enforcing. This is a targeted change, not a global mode switch. The administrator asked to set the SELinux mode to permissive, which affects all domains, so this command is too narrow.
- ✗
restorecon -R /
Why it's wrong here
restorecon relabels files to match the SELinux policy context and does not change the SELinux mode. Running it recursively on the root filesystem could be disruptive and would not make the system permissive. It addresses file context mismatches, not global enforcement behavior, so it fails the stated objective.
Go deeper
Related to this question
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.