Courseiva
Manage security →easyMultiple Choice

EX200 Manage security Practice Question

A junior administrator is tasked with setting up SELinux contexts on a Red Hat Enterprise Linux 9 server to allow Apache HTTPD to read and write to a custom directory /var/www/customcontent. The directory already exists and contains several files. The administrator has confirmed that the httpd service is running and SELinux is in enforcing mode. After changing the context to httpd_sys_content_t using chcon, the web server can read files but cannot write to the directory. The administrator needs to fix this without disabling SELinux or changing the mode to permissive. Which of the following is the correct next step?

⚠ Common exam trap

Test-takers frequently think setting the context with chcon or semanage alone is sufficient, but they overlook the need to run restorecon to apply the new default context to existing files, or they confuse httpd_sys_content_t (read-only) with httpd_sys_rw_content_t (read-write).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run restorecon -R -v /var/www/customcontent after setting the default context with semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/customcontent(/.*)?'

The directory already has the httpd_sys_content_t type, which allows reading but not writing. To enable write access, the correct type is httpd_sys_rw_content_t. Option B correctly uses semanage fcontext to set the default context to this type and then runs restorecon to apply it persistently, ensuring Apache can both read and write.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the SELinux boolean httpd_enable_homedirs to on using setsebool.

    Why it's wrong here

    The boolean httpd_enable_homedirs is specifically designed to control whether Apache can access user home directories (e.g., public_html via mod_userdir). It has no bearing on the labeling or access rights for a custom directory under /var/www. Even if enabled, it would not grant httpd write access to /var/www/customcontent; that requires a proper file context with an httpd_writable type. Thus, toggling this boolean is irrelevant to the stated requirement.

  • ✓

    Run restorecon -R -v /var/www/customcontent after setting the default context with semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/customcontent(/.*)?'

    Why this is correct

    The correct approach uses semanage fcontext to add a persistent default rule that maps /var/www/customcontent and its contents to the httpd_sys_rw_content_t type. Running restorecon -R -v then applies that rule immediately, relabeling existing files to match the policy. The -R flag ensures recursive relabeling and -v shows which files are being relabeled. This combination establishes the writable SELinux type persistently, so future files created in that directory inherit the correct context.

  • ✗

    Change the context to httpd_sys_content_t using chcon -R -t httpd_sys_content_t /var/www/customcontent

    Why it's wrong here

    chcon changes the SELinux context immediately, but the change is temporary and will be reverted by any subsequent restorecon or filesystem relabel. Additionally, httpd_sys_content_t is read-only for the web server; it permits Apache to read and serve static content but not to write or modify files. Since the requirement is to allow httpd to write, using this type would deny write operations. A persistent semanage fcontext rule with httpd_sys_rw_content_t is needed.

  • ✗

    Run semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/customcontent(/.*)?' without running restorecon.

    Why it's wrong here

    semanage fcontext only adds a rule to the SELinux policy database that defines the default context for a path; it does not modify the current context of any existing files. Without running restorecon, the actual files in /var/www/customcontent retain their original context (likely default_t or unlabeled), which Apache cannot access or write to. The rule only takes effect when restorecon is executed or when new files are created in the directory. Therefore, omitting restorecon leaves the directory incorrectly labeled, so this option is incomplete.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.