Courseiva
hardMultiple Choice

XK0-006 Practice Question: A system administrator installs a new application…

A system administrator installs a new application that is failing to write to its configuration file in /etc. SELinux is enforcing. Which command would show the relevant SELinux denials?

⚠ Common exam trap

CompTIA often tests the distinction between commands that show denials (ausearch) versus commands that interpret or explain denials (audit2why, sealert), leading candidates to pick a tool that requires the denial data as input rather than one that retrieves it directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ausearch -m avc -ts recent

The `ausearch -m avc -ts recent` command queries the audit log for AVC (Access Vector Cache) denial messages, which are the specific SELinux denials logged when a process is blocked from accessing a resource. This is the direct way to view recent SELinux denials in an enforcing mode environment, as it filters audit records by message type (AVC) and time range (recent).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    sealert

    Why it's wrong here

    sealert parses the audit log into human-readable reports, but it requires the setroubleshoot-server package and does not itself generate denials. It is tempting because it summarises AVC messages, and would be correct on a system where setroubleshoot is installed and you want plain-language explanations of why SELinux blocked an action.

  • ✓

    ausearch -m avc -ts recent

    Why this is correct

    SELinux denials are logged as AVC messages in the audit log. The ausearch command with -m avc filters specifically for these access vector cache denials, and -ts recent limits output to recent events, directly revealing why the application cannot write to /etc.

  • ✗

    getenforce

    Why it's wrong here

    getenforce only prints the current SELinux mode (Enforcing, Permissive or Disabled); it reports no AVC denials, so it cannot reveal why the write to /etc was blocked. It is tempting because confirming enforcement is a sensible first check, and it would be the right command when verifying whether SELinux is active before troubleshooting policy.

  • ✗

    audit2why

    Why it's wrong here

    audit2why translates an existing denial into plain-language reasons; it does not itself display the raw AVC denials. It is the right tool after collecting denials to explain why a specific access was refused, not to surface the denial events.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.