XK0-006 Security Practice Question
An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?
⚠ Common exam trap
XK0-006 often tests the misinterpretation of 'unconfined' as permissive mode or disabled SELinux, when it actually refers to the domain type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process is running in an unconfined domain.
The context 'unconfined_u:unconfined_r:unconfined_t:s0' indicates that the process is running in the unconfined domain (unconfined_t). In SELinux, processes in the unconfined domain are not restricted by the targeted policy, meaning they have full access subject to standard Linux permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process is running in permissive mode.
Why it's wrong here
Permissive mode still assigns confined domain types to processes and only logs denials, so unconfined_t does not indicate permissive. It is tempting because permissive does not block operations, but it would be the correct choice when a confined process shows a domain type and denials appear in the audit log without being enforced.
- ✓
The process is running in an unconfined domain.
Why this is correct
The unconfined_t type places the process outside SELinux policy enforcement, so type enforcement rules do not restrict it. Confined domains such as httpd_t are limited by policy; unconfined processes retain standard discretionary access controls only.
- ✗
SELinux is disabled.
Why it's wrong here
SELinux is enabled and enforcing or permissive; a disabled system would show no SELinux context labels at all. It is tempting because unconfined_t sounds unrestricted, but the label itself is assigned by SELinux, and it would be the correct conclusion only if getenforce returned Disabled.
- ✗
The process is confined by a targeted policy.
Why it's wrong here
The unconfined_t type indicates the process runs outside SELinux confinement, so it is not confined by a targeted policy. It is tempting because targeted policy is the default SELinux mode, and a confined process would show a specific domain type such as httpd_t rather than unconfined_t.
Go deeper
Related to this question
Learn chapter
Linux Fundamentals and History
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.