XK0-006 Security Practice Question
A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)
⚠ Common exam trap
XK0-006 often tests the distinction between commands that modify SELinux contexts versus those that only display or change enforcement mode, and candidates may incorrectly choose 'fixfiles relabel' for a single file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
restorecon -R /path/to/file
Option B (restorecon -R /path/to/file) is correct because restorecon resets a file or directory's SELinux context to the default defined by the system's policy, and the -R flag applies this recursively to the specified path, which is exactly what is needed to fix an incorrect context. Option C (chcon -t httpd_sys_content_t /path/to/file) is correct because chcon directly changes the SELinux type of a file or directory to the specified context (here httpd_sys_content_t), allowing an administrator to manually set the correct context. Option A (setenforce 0) only switches SELinux to permissive mode and does not relabel anything. Option D (fixfiles relabel) is a broader relabeling utility typically used to relabel the entire filesystem or all files, not to target a specific file or directory's context. Option E (ls -Z) merely displays SELinux contexts and does not modify them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
setenforce 0
Why it's wrong here
setenforce toggles SELinux between enforcing and permissive modes at runtime; it changes enforcement behaviour, not file context labels. It tempts because it is an SELinux troubleshooting command, but relabelling requires restorecon or chcon, which write the correct context to the file or directory.
- ✓
restorecon -R /path/to/file
Why this is correct
The `restorecon -R /path/to/file` command recursively resets SELinux contexts to the values defined in the system's file-context policy, satisfying the requirement to relabel a file or directory to its correct context. Unlike `chcon`, which applies a manually specified context, `restorecon` reads the persistent policy mapping, ensuring the audit finding is resolved durably.
- ✓
chcon -t httpd_sys_content_t /path/to/file
Why this is correct
The `chcon` command directly changes an SELinux security context, and the `-t` flag specifies the target type, here `httpd_sys_content_t`. This satisfies the audit's requirement to relabel the file to the correct context, resolving the incorrect context without altering the persistent policy database.
- ✗
fixfiles relabel
Why it's wrong here
fixfiles relabel rewrites every file on the filesystem to its policy default, which is a bulk remediation for a corrupted label store, not a targeted correction of one service's context. It is tempting as the obvious 'fix labels' command, and would be correct after a policy reload or restorecon failure affecting many paths.
- ✗
ls -Z
Why it's wrong here
ls -Z only displays the current SELinux user, role, type and level of files; it writes nothing, so the mislabelled service context persists. It is tempting because it is the standard diagnostic for inspecting contexts before deciding what to change, and would be correct when auditing or verifying labels rather than repairing them.
Go deeper
Related to this question
Learn chapter
Navigating the Filesystem
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.