EX200 Manage security Practice Question
A web server is running in enforcing mode with SELinux, but Apache cannot read content in a custom directory /web. The directory has been labeled correctly with httpd_sys_content_t. However, access is still denied. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates focus solely on SELinux context and booleans, forgetting that DAC permissions are evaluated first and can block access even when SELinux labels are perfectly correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The directory has incorrect permissions of 700.
Even though the SELinux context is correctly set to httpd_sys_content_t, the directory has permissions of 700 (rwx------). This means only the owner (typically root) can read, write, or execute the directory. The Apache httpd process runs as the 'apache' or 'httpd' user, which is not the owner, so it is denied read access. SELinux enforces its own policy, but DAC (Discretionary Access Control) permissions are checked first; if DAC denies access, SELinux never gets to evaluate the context match.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SELinux boolean httpd_enable_homedirs is off.
Why it's wrong here
The httpd_enable_homedirs boolean specifically permits Apache to read user home directories for public_html content, not custom web content directories. Since the failing directory is custom, this boolean is not involved in the denial. Toggling it would have no effect; the proper fix would be to set an appropriate SELinux type on the directory itself.
- ✗
The httpd process is running in permissive mode.
Why it's wrong here
Permissive mode is a domain-wide SELinux state: if the httpd_t domain were permissive, the kernel would log an AVC denial but still allow the file access. A permissive domain cannot cause a permission failure, so the presence of a denial actually proves httpd_t is enforcing. Therefore, this answer is contradictory and cannot explain the web server's inability to read the directory.
- ✓
The directory has incorrect permissions of 700.
Why this is correct
A directory mode of 700 grants full permissions only to its owner, which is typically root, while the httpd process runs as the non-owner user apache (or www-data). That places the daemon in the 'other' permission class, which has no read or execute rights, so even an otherwise correct SELinux context and enabling booleans won't help because DAC checks are evaluated first. The fix is to use a mode like 755, or 750 with proper group ownership, so the web server can traverse and read the content.
- ✗
The files are labeled with default_t.
Why it's wrong here
The question stem explicitly states that the files' SELinux context is correct, so labeling them with default_t would contradict the given facts. In practice, default_t is a generic, fallback label that httpd_t is not permitted to read under the normal httpd policy, which would indeed cause an AVC denial if it were actually applied. Because the context is specified as correct, this option cannot be the cause of the problem.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.