Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?

⚠ Common exam trap

XK0-006 often tests the misinterpretation of 'unconfined' as permissive mode or disabled SELinux, when it actually refers to the domain type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process is running in an unconfined domain.

The context 'unconfined_u:unconfined_r:unconfined_t:s0' indicates that the process is running in the unconfined domain (unconfined_t). In SELinux, processes in the unconfined domain are not restricted by the targeted policy, meaning they have full access subject to standard Linux permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process is running in permissive mode.

    Why it's wrong here

    Permissive mode still assigns confined domain types to processes and only logs denials, so unconfined_t does not indicate permissive. It is tempting because permissive does not block operations, but it would be the correct choice when a confined process shows a domain type and denials appear in the audit log without being enforced.

  • ✓

    The process is running in an unconfined domain.

    Why this is correct

    The unconfined_t type places the process outside SELinux policy enforcement, so type enforcement rules do not restrict it. Confined domains such as httpd_t are limited by policy; unconfined processes retain standard discretionary access controls only.

  • ✗

    SELinux is disabled.

    Why it's wrong here

    SELinux is enabled and enforcing or permissive; a disabled system would show no SELinux context labels at all. It is tempting because unconfined_t sounds unrestricted, but the label itself is assigned by SELinux, and it would be the correct conclusion only if getenforce returned Disabled.

  • ✗

    The process is confined by a targeted policy.

    Why it's wrong here

    The unconfined_t type indicates the process runs outside SELinux confinement, so it is not confined by a targeted policy. It is tempting because targeted policy is the default SELinux mode, and a confined process would show a specific domain type such as httpd_t rather than unconfined_t.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.