A security engineer needs to manage Mandatory Access Control (MAC) settings on a Red Hat Enterprise Linux (RHEL) system. Which TWO commands are most essential for viewing and modifying the state and file labeling of SELinux?
Trap 1: umask
The umask command is used to set the default file creation permissions for a user or session, but it deals with standard Discretionary Access Control bits. It has no effect on the Mandatory Access Control labels or the operational state of the SELinux subsystem itself, making it irrelevant for MAC management.
Trap 2: iptables
This utility is used for managing the Linux kernel's IPv4 packet filtering rules and NAT. While it is a security tool, it operates at the network layer rather than the host-based Mandatory Access Control layer. It cannot modify SELinux policies, file labels, or the enforcement status of the system.
Trap 3: sysctl
The sysctl command is used to modify kernel parameters at runtime, such as network stack tuning or memory management settings. While some security settings can be toggled here, it is not the primary interface for managing SELinux file labels or switching between Enforcing and Permissive operational modes.
- A
setenforce
This command allows an administrator to switch the SELinux mode between Enforcing and Permissive in real-time without requiring a system reboot. It is a critical tool for troubleshooting permission issues and ensuring that the security policy is actively blocking unauthorized actions on a production system during normal operations.
- B
chcon
The chcon command is used to change the security context of a file or directory. This is necessary when files are moved or created in a way that doesn't inherit the proper SELinux labels. It allows the administrator to manually define the type, role, and user attributes for specific objects.
- C
umask
Why it fails: The umask command is used to set the default file creation permissions for a user or session, but it deals with standard Discretionary Access Control bits. It has no effect on the Mandatory Access Control labels or the operational state of the SELinux subsystem itself, making it irrelevant for MAC management.
- D
iptables
Why it fails: This utility is used for managing the Linux kernel's IPv4 packet filtering rules and NAT. While it is a security tool, it operates at the network layer rather than the host-based Mandatory Access Control layer. It cannot modify SELinux policies, file labels, or the enforcement status of the system.
- E
sysctl
Why it fails: The sysctl command is used to modify kernel parameters at runtime, such as network stack tuning or memory management settings. While some security settings can be toggled here, it is not the primary interface for managing SELinux file labels or switching between Enforcing and Permissive operational modes.