Courseiva
Manage security →mediumMultiple Choice

EX200 Manage security Practice Question

An administrator wants newly created files to be readable and writable only by the owner, and readable by group and others. Which umask value should be set?

⚠ Common exam trap

A common pitfall is confusing the umask as the permissions to grant rather than to subtract. In Red Hat Enterprise Linux, the default file creation mask is 022, which results in files with 644 permissions (rw-r--r--). Candidates often incorrectly select 002 (which would allow group write) or 077 (which would remove all group/other permissions).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

022

The umask value 022 removes write permissions for group and others, while leaving read and execute permissions intact. Since the default base permissions for files are 666 (rw-rw-rw-), applying umask 022 results in 644 (rw-r--r--), which gives the owner read/write access and group/others read-only access — exactly matching the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    027

    Why it's wrong here

    A umask of 027 applies a mask of 0 for owner, 2 for group, and 7 for others to the base permissions of 666 for new files, yielding 640. That grants the owner read/write and the group read, but removes all permissions from others, so files are no longer readable by everyone. Since the requirement is that new files be readable by all, 027 fails because it denies others read access.

  • ✓

    022

    Why this is correct

    With umask 022, the mask removes the write bit from group and others (2 = write) from the base 666, resulting in files with 644. That gives the owner read/write and both the group and others read permission, so every user can read the file. This is the standard, desired value for making newly created files world-readable.

  • ✗

    002

    Why it's wrong here

    A umask of 002 only masks the write bit for others (2), so files retain 664, which includes group write permission. The group is given write access, not just read, which is beyond the stated requirement and could allow unintended modifications. While others can still read, the group's extra write permission makes this umask unsuitable for a simple 'readable by all' goal.

  • ✗

    077

    Why it's wrong here

    Setting umask 077 masks all group and others permissions (7 = read+write+execute) from the base 666, leaving only 600. That gives the owner full read/write but provides no access to either the group or others, so the file is completely unreadable to anyone else. This is a restrictive umask designed for privacy, not for making files readable by all.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.