Courseiva
hardMultiple Choice

XK0-006 Practice Question: An Apache web server (httpd) is serving content…

An Apache web server (httpd) is serving content from a custom directory /webapps/company. The root directory is labeled with the default_t context, causing httpd to be denied access. Which command should the administrator use to persistently relabel the directory for httpd access?

⚠ Common exam trap

It's easy for candidates to confuse `chcon` (immediate but non-persistent) with `semanage fcontext` (persistent via policy), or they incorrectly assume `restorecon` can change the context to a non-default type when it only restores the type defined in the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

semanage fcontext -a -t httpd_sys_content_t '/webapps/company(/.*)?'

`semanage fcontext` modifies the SELinux file context policy persistently, and the regex `/webapps/company(/.*)?` ensures the rule applies to the directory and all its contents. This is necessary because `restorecon` (option A) only applies the default context from the policy, which is `default_t` for this custom path, and `chcon` (option B) is non-persistent and will be overwritten by a file system relabel. The `setsebool` (option C) controls a boolean for user content, not the file context of a custom directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    restorecon -v /webapps/company

    Why it's wrong here

    restorecon resets labels to whatever the active SELinux policy already defines for that path. Since no fcontext rule maps /webapps/company to httpd_sys_content_t, it restores default_t and access stays denied. It is the right tool only after a persistent mapping exists.

  • ✗

    chcon -t httpd_sys_content_t /webapps/company

    Why it's wrong here

    chcon applies a label change directly to the inode, but it is not recorded in the SELinux policy, so a subsequent restorecon or relabel reverts the directory to default_t. It suits one-off, temporary testing contexts. Persistence requires a fcontext rule plus restorecon.

  • ✗

    setsebool -P httpd_read_user_content on

    Why it's wrong here

    setsebool toggles a boolean governing httpd's access to user home content, not file contexts on /webapps/company, so the denial persists. It tempts because booleans commonly fix SELinux denials, and it would be correct if httpd needed to serve content from users' home directories.

  • ✓

    semanage fcontext -a -t httpd_sys_content_t '/webapps/company(/.*)?'

    Why this is correct

    The `semanage fcontext -a -t httpd_sys_content_t` command writes a persistent mapping into the SELinux file-context policy, so `/webapps/company` and its contents inherit `httpd_sys_content_t` rather than `default_t`. This satisfies the requirement for a lasting relabel that survives `restorecon` and reboot, unlike transient `chcon` changes.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.