mediumMultiple Choice
How to Set a Persistent SELinux File Context Using semanage fcontext
Scenario: A cloud hosting company uses SELinux in enforcing mode on all Linux servers. A developer reports that a custom web application running under Apache (httpd) is unable to write log files to /var/log/myapp/. The directory /var/log/myapp/ has permissions 755 and is owned by root:root. The httpd process runs as the 'apache' user. The administrator checks SELinux context: /var/log/myapp is labeled with default_t type. The administrator wants to allow httpd to write to this directory while maintaining security. Which command should the administrator run?
⚠ Common exam trap
Watch out — candidates often choose chcon (Option C) because it works immediately, but they overlook that it is not persistent and will be overwritten by restorecon or policy updates, whereas semanage fcontext followed by restorecon is the correct persistent method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'semanage fcontext -a -t httpd_log_t "/var/log/myapp(/.*)?"' and then 'restorecon -Rv /var/log/myapp'
It permanently relabels the directory with the httpd_log_t SELinux type, which is specifically designed to allow Apache (httpd) to write log files. The semanage fcontext command adds a file context mapping to the SELinux policy database, and restorecon applies that mapping to the filesystem. This approach maintains SELinux enforcing mode and does not rely on temporary changes like chcon or insecure workarounds like disabling SELinux.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change ownership with 'chown apache:apache /var/log/myapp'
Why it's wrong here
Ownership is irrelevant here: the directory is already 755, and SELinux type enforcement, not Unix permissions, is blocking httpd from writing to a default_t directory. chown is tempting because permission-denied errors often stem from ownership, and it would be correct if standard DAC permissions were the actual cause.
- ✗
Run 'setenforce 0' to disable SELinux
Why it's wrong here
Disabling enforcement removes all SELinux confinement system-wide, abandoning the security posture the scenario requires rather than granting httpd write access to this one directory. It is tempting as a quick diagnostic, and setenforce 0 is legitimate for temporarily testing whether SELinux is the cause of a failure.
- ✗
Run 'chcon -t httpd_log_t /var/log/myapp'
Why it's wrong here
chcon applies only a temporary label change that restorecon or a relabel will revert, and httpd_log_t is the type for httpd's own log files, not for a custom directory under /var/log. It is tempting because chcon does set an SELinux type on a path, which is the right approach when the label merely needs correcting.
- ✓
Run 'semanage fcontext -a -t httpd_log_t "/var/log/myapp(/.*)?"' and then 'restorecon -Rv /var/log/myapp'
Why this is correct
Labeling the directory with the httpd_log_t type grants httpd write access under SELinux, satisfying the enforcing-mode constraint that default_t denies. The semanage fcontext command adds the persistent file-context rule, and restorecon applies it to the existing files.
Go deeper
Related to this question
Learn chapter
User and Group Administration
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.