A security team wants to implement mandatory access control (MAC) on a Linux server to confine a potentially vulnerable daemon. Which TWO of the following technologies can be used for this purpose?
Trap 1: sudo
sudo grants per-user privilege escalation via the sudoers file; it is discretionary, not mandatory, since administrators define who may run what. MAC confines processes through kernel-enforced, centrally compiled policy independent of user identity. sudo would suit delegating specific administrative commands to named operators, not containing a daemon's syscall and file access.
Trap 2: TCP wrappers
TCP wrappers filter inbound connections by source address and service name through hosts.allow and hosts.deny; they enforce no per-process, label-based confinement, so a compromised daemon retains full access to files and sockets. They are correct for host-level network access control, not mandatory access control.
Trap 3: iptables
iptables filters network packets by address, port and protocol; it cannot constrain a daemon's filesystem, capability or syscall access, which is what MAC confinement requires. It would be the right choice for restricting inbound or outbound traffic to specific hosts and services, not for sandboxing a vulnerable local process.
- A
sudo
Why it fails: sudo grants per-user privilege escalation via the sudoers file; it is discretionary, not mandatory, since administrators define who may run what. MAC confines processes through kernel-enforced, centrally compiled policy independent of user identity. sudo would suit delegating specific administrative commands to named operators, not containing a daemon's syscall and file access.
- B
AppArmor
AppArmor enforces mandatory access control by applying per-program path-based profiles that confine a daemon's file, network and capability usage, independently of discretionary permissions. This satisfies the requirement to confine a potentially vulnerable daemon on Linux.
- C
SELinux
SELinux implements mandatory access control through type enforcement, assigning labels to processes and objects so a confined daemon can only access permitted types. This satisfies the requirement to confine a potentially vulnerable daemon independently of standard Unix permissions.
- D
TCP wrappers
Why it fails: TCP wrappers filter inbound connections by source address and service name through hosts.allow and hosts.deny; they enforce no per-process, label-based confinement, so a compromised daemon retains full access to files and sockets. They are correct for host-level network access control, not mandatory access control.
- E
iptables
Why it fails: iptables filters network packets by address, port and protocol; it cannot constrain a daemon's filesystem, capability or syscall access, which is what MAC confinement requires. It would be the right choice for restricting inbound or outbound traffic to specific hosts and services, not for sandboxing a vulnerable local process.