Courseiva
mediumMultiple Choice

XK0-006 Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```
type=AVC msg=audit(1234567890.123:45): avc: denied { write } for pid=1234 comm="httpd" name="app.log" dev=sda1 ino=56789 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:var_log_t:s0 tclass=file
```

Refer to the exhibit. A web application running under Apache cannot write to /var/log/app.log. The file has permissions 664 and is owned by apache. What is the correct action to allow writes while maintaining SELinux policies?

⚠ Common exam trap

The trap here is that candidates see the file is owned by apache with 664 permissions and assume the issue is file ownership or permissions, overlooking that SELinux enforces its own access controls independent of standard Linux permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the SELinux context of the file to httpd_log_t.

The file /var/log/app.log has permissions 664 and is owned by apache, so the web server should be able to write to it. However, SELinux is blocking the write because the file's SELinux context does not match the type expected for files that Apache (httpd) is allowed to write to. Changing the SELinux context to httpd_log_t tells SELinux that this file is a log file that httpd can write to, which resolves the denial while keeping SELinux enforcing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the ownership to root.

    Why it's wrong here

    Ownership is already apache and mode 664 grants group write, so the denial stems from an SELinux type mismatch on the log file, not Unix ownership. Changing ownership to root would worsen access. Root ownership is correct for system binaries or protected configuration files, not for a daemon's own writable log.

  • ✓

    Change the SELinux context of the file to httpd_log_t.

    Why this is correct

    Assigning httpd_log_t lets the Apache process, confined by the httpd_t domain, write to the file under SELinux type enforcement. The 664 mode and apache ownership already permit Unix-level writes, so the remaining constraint is the file's label; httpd_log_t is the type httpd_t is allowed to append to.

  • ✗

    Set the httpd_can_network_connect boolean.

    Why it's wrong here

    The httpd_can_network_connect boolean governs outbound network connections from httpd, not filesystem writes, so toggling it leaves the SELinux denial on /var/log/app.log unresolved. That boolean is the right fix when a web application must reach a remote database or API and SELinux blocks the socket.

  • ✗

    Disable SELinux for the httpd daemon.

    Why it's wrong here

    Disabling SELinux enforcement for httpd removes the mandatory access control protecting the whole service, exceeding what a single log-write denial warrants and breaching the requirement to maintain policies. Per-domain disabling is chosen only when a vendor application is fundamentally incompatible with targeted policy and no custom module can be written.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.