Courseiva
Operate running systems →hardMultiple Choice

EX200 Operate running systems Practice Question

After restoring files from backup, an SELinux context of a directory is not correct. Which command will restore the file contexts to the system defaults?

⚠ Common exam trap

A common mix-up: candidates confuse `chcon` (which sets an arbitrary context) with `restorecon` (which sets the default context from policy), or they think `semanage fcontext` directly modifies file contexts rather than the policy database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

restorecon -R /directory

The `restorecon -R /directory` command reads the default SELinux contexts from the policy (stored in the file_contexts database) and applies them recursively to the specified directory. This is the standard method to reset file contexts to system defaults after a restore or misconfiguration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chcon -R default_t /directory

    Why it's wrong here

    chcon -R default_t /directory directly writes the specified SELinux type to the files' extended attributes, but it does not consult the policy's file_contexts rules. The label default_t is a generic unconfined type, not the proper context assigned to regular directories by the installed policy, so this would create further mislabeling. Additionally, any label set by chcon is temporary: the next full filesystem relabel or restorecon will overwrite it based on policy defaults.

  • ✓

    restorecon -R /directory

    Why this is correct

    restorecon -R /directory reads the current file_contexts database to determine the policy-defined default context for every path under /directory and, with -R, recursively resets the security.selinux extended attribute on any file whose label differs from that default. It does not alter permissions or ownership and only touches files that are actually mislabeled, making it the standard, safe repair tool after a backup restore. Unlike chcon, it uses authoritative policy rules, so it guarantees a consistent context that will survive a future autorelabel.

  • ✗

    semanage fcontext -R /directory

    Why it's wrong here

    semanage fcontext -R /directory manages the persistent policy rules that associate path patterns with SELinux contexts, but it never directly modifies the extended attributes of existing files. In this command, -R means 'replace' for an existing rule (or is misread as recursive), not recursion over a directory; a newly added or modified fcontext rule only takes effect after you run restorecon on the target paths. Therefore this command changes policy configuration but leaves the restored files mislabeled until a separate relabeling step.

  • ✗

    setfiles -v /directory

    Why it's wrong here

    setfiles -v /directory is a low-level utility designed to apply a file_contexts specification to an entire filesystem or a large file tree, typically invoked during initial system installation or a full autorelabel, not for a single user directory. It accepts a file_contexts file as an argument and traverses the given path recursively, outputting verbose information with -v, but this approach is overkill and risks relabeling unrelated system directories if the path or context files are not carefully specified. For a targeted repair after a backup restore, restorecon is the proper tool because it relies on the active policy defaults without re-reading a custom specification.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.