Courseiva
Manage security →hardMultiple Choice

EX200 Manage security Practice Question

A company runs a web application on a Red Hat Enterprise Linux 8 server. The application is served by Apache HTTPD, and it requires read/write access to a custom directory /var/www/app_data. The SELinux context for the directory is set to httpd_sys_rw_content_t. Apache runs in enforcing mode. Recently, a new feature was added that requires Apache to connect to a database on the same server via a Unix socket. The database serves on /var/run/mysqld/mysqld.sock. After the feature deployment, the web application fails to connect to the database. The error logs show permission denied on the socket file. The socket file has permissions 660 and is owned by mysql:mysql. SELinux audit logs show AVC denials for httpd_t trying to connect to mysqld_var_run_t. Which of the following solutions should the administrator implement to allow Apache to read the database socket while maintaining security?

⚠ Common exam trap

It's easy for candidates to confuse `httpd_can_connect_db` (for local database connections via Unix sockets) with `httpd_can_network_connect_db` (for remote TCP connections), leading them to choose the wrong boolean when the scenario involves a local socket file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the SELinux boolean httpd_can_connect_db using setsebool -P httpd_can_connect_db on.

The correct solution is to enable the SELinux boolean `httpd_can_connect_db` using `setsebull -P httpd_can_connect_db on`. This boolean specifically allows the `httpd_t` domain to connect to MySQL/MariaDB databases via Unix sockets, which is exactly the scenario described: Apache needs to connect to a local database socket with context `mysqld_var_run_t`. The AVC denial confirms that the default policy blocks this socket connection, and enabling this boolean grants the necessary permission without weakening other security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the SELinux context of the socket file to httpd_sys_rw_content_t using chcon.

    Why it's wrong here

    Changing the socket file's context to httpd_sys_rw_content_t with chcon mislabels it as a web content type, while SELinux assigns dedicated types to Unix sockets such as httpd_var_run_t. chcon only alters the label on the specific file and does not persist after a filesystem relabel, and this context does not grant the permission required for httpd to connect to a local database socket. The proper fix is to toggle the httpd_can_connect_db boolean, not attempt to relabel the socket.

  • ✗

    Enable the SELinux boolean httpd_can_network_connect_db using setsebool -P httpd_can_network_connect_db on.

    Why it's wrong here

    The httpd_can_network_connect_db boolean governs outbound TCP/IP connections from Apache to a remote database server, not local Unix socket connections. Enabling it would leave the local socket path still blocked by SELinux, so the web application would continue to fail when connecting via /var/run/mysql/mysql.sock. You need httpd_can_connect_db instead, which specifically permits Apache to connect to database server sockets on the local filesystem.

  • ✓

    Enable the SELinux boolean httpd_can_connect_db using setsebool -P httpd_can_connect_db on.

    Why this is correct

    This is the correct boolean because httpd_can_connect_db allows the httpd daemon to connect to a database through local Unix socket files, such as /var/run/mysql/mysql.sock, while leaving network controls unchanged. Using setsebool with -P is essential because it writes the change to the persistent policy so the permission survives a reboot, matching the intended production configuration. The boolean directly addresses the SELinux denial shown in the audit log instead of masking the problem.

  • ✗

    Use semanage to add a context mapping for the socket file to httpd_var_run_t and set the httpd to permissive mode.

    Why it's wrong here

    Using semanage fcontext to map a socket file to httpd_var_run_t is unnecessary because sockets already receive a type like httpd_var_run_t through the default labeling process, and semanage without restorecon would not even change the existing label. More critically, switching httpd to permissive mode disables SELinux protection for the entire daemon, which is an unacceptable security trade-off and does not actually diagnose whether the boolean policy is correct. Even with a proper socket context, SELinux still requires httpd_can_connect_db to be enabled for the connection to succeed.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.