A security administrator is configuring a Linux server to enforce mandatory access control (MAC). Which of the following tools provides MAC on Linux?
SELinux enforces mandatory access control through type enforcement, role-based access control and multi-level security, applying kernel-level policy labels that constrain every process and file regardless of user discretion. AppArmor and standard permissions do not provide the same comprehensive MAC model on Linux.
Why this answer
SELinux and AppArmor are Linux security modules that implement mandatory access control policies beyond traditional discretionary access control.