Courseiva
Manage security →mediumMultiple Choice

EX200 Manage security Practice Question

Network Topology
-rw-rrRefer to the exhibit.# ls -lZ /var/www/html/index.html

A user reports that the Apache web server cannot serve the file /var/www/html/index.html on a RHEL 9 system when SELinux is in enforcing mode. Given the exhibit output, what is the most likely cause?

⚠ Common exam trap

The trap here is that candidates often focus on file permissions or ownership (options B and C) because they are familiar from non-SELinux systems, but the question explicitly states SELinux is in enforcing mode, which overrides DAC permissions when a type mismatch exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SELinux context of the file is incorrect for web serving.

The default SELinux context for files served by Apache in /var/www/html is `httpd_sys_content_t`. If the file has a different context (e.g., `unconfined_u:object_r:admin_home_t:s0`), SELinux will deny Apache read access even if standard Linux permissions are permissive. The `ls -Z` output would reveal the mismatch, and `restorecon -v /var/www/html/index.html` would fix it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewalld service is blocking HTTP traffic on port 80.

    Why it's wrong here

    A firewalld block on port 80 would prevent clients from reaching the Apache server at the network level, typically yielding connection timeouts or resets, not an internal file-access error. Here the symptom is specifically that Apache cannot serve the file, and the exhibit shows an SELinux context, not a firewall rule. Since firewall rules govern network traffic rather than filesystem permissions, this is not the cause.

  • ✗

    The file is owned by root and Apache cannot read it.

    Why it's wrong here

    Ownership by root alone does not prevent Apache from reading a file, as long as the file's permission bits grant read access to the 'other' class. Red Hat systems routinely serve files owned by root with mode 644, and httpd accesses those files because the world-read bit is set. In this case, the apache user is not the owner, but SELinux is the layer that is denying access—not the ownership.

  • ✗

    The file permissions do not allow the apache user to read the file.

    Why it's wrong here

    The permissions on this file are 644, which means the owner has read/write, the group has read, and all other users have read. Since the apache user is neither the owner nor in the group, it falls under 'other' and the read bit is set, so the DAC (Discretionary Access Control) permissions permit Apache to open the file. If permissions were preventing access, you would see an EACCES error before SELinux is consulted, but here the underlying issue is the SELinux label, not the mode bits.

  • ✓

    The SELinux context of the file is incorrect for web serving.

    Why this is correct

    The SELinux context user_home_t is intended for files in user home directories, and the httpd_t domain is not allowed to read files with that type by default. Even with correct Unix permissions, Apache will receive a permission denial from SELinux because the file is not labeled with a type such as httpd_sys_content_t or public_content_t. This is a classic SELinux mislabeling problem, easily verified with ls -Z and fixed with restorecon or semanage fcontext.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.