hardMultiple Choice
XK0-006 Practice Question: A system administrator installs a new application…
A system administrator installs a new application that is failing to write to its configuration file in /etc. SELinux is enforcing. Which command would show the relevant SELinux denials?
⚠ Common exam trap
CompTIA often tests the distinction between commands that show denials (ausearch) versus commands that interpret or explain denials (audit2why, sealert), leading candidates to pick a tool that requires the denial data as input rather than one that retrieves it directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ausearch -m avc -ts recent
The `ausearch -m avc -ts recent` command queries the audit log for AVC (Access Vector Cache) denial messages, which are the specific SELinux denials logged when a process is blocked from accessing a resource. This is the direct way to view recent SELinux denials in an enforcing mode environment, as it filters audit records by message type (AVC) and time range (recent).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
sealert
Why it's wrong here
sealert parses the audit log into human-readable reports, but it requires the setroubleshoot-server package and does not itself generate denials. It is tempting because it summarises AVC messages, and would be correct on a system where setroubleshoot is installed and you want plain-language explanations of why SELinux blocked an action.
- ✓
ausearch -m avc -ts recent
Why this is correct
SELinux denials are logged as AVC messages in the audit log. The ausearch command with -m avc filters specifically for these access vector cache denials, and -ts recent limits output to recent events, directly revealing why the application cannot write to /etc.
- ✗
getenforce
Why it's wrong here
getenforce only prints the current SELinux mode (Enforcing, Permissive or Disabled); it reports no AVC denials, so it cannot reveal why the write to /etc was blocked. It is tempting because confirming enforcement is a sensible first check, and it would be the right command when verifying whether SELinux is active before troubleshooting policy.
- ✗
audit2why
Why it's wrong here
audit2why translates an existing denial into plain-language reasons; it does not itself display the raw AVC denials. It is the right tool after collecting denials to explain why a specific access was refused, not to surface the denial events.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.