Courseiva
Manage security →easyMultiple Choice

EX200 Manage security Practice Question

A security policy requires that all files in /home have the default SELinux context for user home directories. Which command recursively restores the default context?

⚠ Common exam trap

Many candidates confuse `restorecon` with `chcon` or `semanage fcontext`, mistakenly thinking that adding a rule with `semanage` or manually setting a context with `chcon` is sufficient, when in fact only `restorecon` (or `setfiles`) applies the policy-defined default context to existing files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

restorecon -Rv /home

`restorecon -Rv /home` recursively resets the SELinux context of all files under `/home` to the default type defined in the SELinux policy for user home directories (typically `user_home_t`). The `-R` flag enables recursion, and `-v` provides verbose output, ensuring compliance with the security policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    restorecon -Rv /home

    Why this is correct

    restorecon -Rv /home is correct because it rereads the active SELinux file context policy (from /etc/selinux/*/contexts/files) and applies the proper default type to every file and directory under /home. The -R flag makes it recursive, and -v shows exactly what is being relabeled, so this command directly satisfies the security policy requirement without altering policy definitions.

  • ✗

    semanage fcontext -a -t user_home_t /home

    Why it's wrong here

    semanage fcontext -a -t user_home_t /home only adds or modifies a persistent rule in the SELinux policy database; it does not change the labels currently on the filesystem. Even after the rule is added, the existing files in /home retain their current contexts until something like restorecon or setfiles is executed to apply the new policy rule, so running this command alone would not make the system compliant.

  • ✗

    chcon -Rv default_t /home

    Why it's wrong here

    chcon -Rv default_t /home manually writes the literal type 'default_t' to every file and directory under /home without consulting the SELinux policy. This is not a restoration of correct defaults; it blindly forces a possibly incorrect or non-existent default label and the change is not persistent across file system relabels, whereas a proper restoration would use the policy-defined type for each file, such as home_root_t for /home and user_home_t for home directories.

  • ✗

    setfiles -Rv /home

    Why it's wrong here

    setfiles -Rv /home is incorrect because setfiles requires a file contexts specification file to be passed with the -f option; without it, the command has no criteria to determine what labels should be applied. Even when a specification file is provided, setfiles is a lower-level tool typically used at boot or during policy reloads, and it is not the standard utility for recursively restoring contexts on a live system—restorecon is the intended, policy-aware command for that purpose.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.