Courseiva

EX200 · domain

Manage security

This domain covers host-based security on RHEL: configuring firewalld zones, services, ports, and rich rules with firewall-cmd, hardening sshd via /etc/ssh/sshd_config, and managing SELinux modes and file contexts with getenforce, setenforce, semanage, and restorecon. EX200 tests these through hands-on tasks you perform on a live system, not multiple-choice recall.

38 questions11 easy18 medium9 hard

Focused practice

Practice Manage security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage security

You must configure firewalld with firewall-cmd and harden SSH in sshd_config, then verify with firewall-cmd --list-all and ssh. The single most important thing: always use --permanent and --reload together, and restart sshd after any config change.

Opening or restricting ports and services with firewall-cmd --permanent plus --reload, and assigning interfaces to zones

Hardening sshd_config: disabling root login, password authentication, and restricting users or groups

Creating rich rules to limit source networks to specific ports, such as allowing 10.0.1.0/24 to port 2222

Managing SELinux with getenforce, setenforce, semanage fcontext, and restorecon to fix denied access

Watch out for

Common Manage security exam traps

  • ▸Adding firewall rules without --permanent, so changes vanish after reload or reboot; or forgetting --reload so the running config never updates.
  • ▸Editing sshd_config but not restarting sshd, or setting PermitRootLogin and PasswordAuthentication incorrectly so key-only login still fails.
  • ▸Changing SELinux to permissive instead of fixing the file context with semanage fcontext and restorecon, which loses points on grading.

Question index

All Manage security questions (38)

Click any question to see the full explanation, or start a practice session above.

1

A system administrator needs to allow members of the 'developers' group to run any command as root without being prompted for a password. Which sudoers configuration line should be added?

Easy
2

A file has been assigned an incorrect SELinux context, preventing a service from accessing it. Which command restores the default SELinux context for that file?

Medium
3

Order the steps to configure firewall rules to allow HTTP and HTTPS traffic using firewalld.

Medium
4

An administrator needs to grant user 'dev' the ability to execute /usr/local/bin/deploy.sh as root without a password, but no other commands. Which sudoers entry accomplishes this?

Hard
5

A system administrator is managing a Red Hat Enterprise Linux 9 web server running Apache httpd. The server hosts a custom application that stores its files in /var/www/custom. The administrator has set ownership to apache:apache and file permissions to 755. However, when users access the web application, they receive a 'Forbidden' error. The httpd service is running, and SELinux is in enforcing mode. The administrator checks the SELinux context of the /var/www/custom directory and sees 'unconfined_u:object_r:default_t:s0'. What should the administrator do to resolve the issue without disabling SELinux?

Medium
6

Which TWO commands can be used to display SELinux contexts of files? (Choose two.)

Easy
7

Match each networking term to its definition.

Medium
8

Refer to the exhibit. A web server is serving content from /var/www/html. SELinux is in enforcing mode. The web client reports 'Forbidden'. What is the most likely cause?

Hard
9

A company runs a web application on a Red Hat Enterprise Linux 8 server. The application is served by Apache HTTPD, and it requires read/write access to a custom directory /var/www/app_data. The SELinux context for the directory is set to httpd_sys_rw_content_t. Apache runs in enforcing mode. Recently, a new feature was added that requires Apache to connect to a database on the same server via a Unix socket. The database serves on /var/run/mysqld/mysqld.sock. After the feature deployment, the web application fails to connect to the database. The error logs show permission denied on the socket file. The socket file has permissions 660 and is owned by mysql:mysql. SELinux audit logs show AVC denials for httpd_t trying to connect to mysqld_var_run_t. Which of the following solutions should the administrator implement to allow Apache to read the database socket while maintaining security?

Hard
10

After configuring sudo, a user reports: 'sudo: unable to open /etc/sudoers: Permission denied'. The admin checks the file permissions and sees '-rw-r-----' owned by root:root. What is the most likely cause?

Medium
11

A web server is running in enforcing mode with SELinux, but Apache cannot read content in a custom directory /web. The directory has been labeled correctly with httpd_sys_content_t. However, access is still denied. What is the most likely cause?

Medium
12

Which file contains the hashed passwords for local user accounts?

Easy
13

A user reports that the Apache web server cannot serve the file /var/www/html/index.html on a RHEL 9 system when SELinux is in enforcing mode. Given the exhibit output, what is the most likely cause?

Medium
14

A system administrator wants to allow user 'jdoe' to execute any command as root via sudo without being prompted for a password, but only from the host 'client1.example.com'. Which sudoers rule achieves this?

Hard
15

Which THREE commands are used to manage SELinux file security contexts? (Select exactly three.)

Medium
16

A security policy requires that all files in /home have the default SELinux context for user home directories. Which command recursively restores the default context?

Easy
17

A server's firewall is managed by firewalld. The admin adds a rule to allow HTTPS traffic to the public zone, but clients still cannot connect. What is the most likely cause?

Medium
18

An administrator wants newly created files to be readable and writable only by the owner, and readable by group and others. Which umask value should be set?

Medium
19

Which three statements about firewalld zones are correct? (Choose three.)

Medium
20

Refer to the exhibit. A CGI script located at /var/www/cgi-bin/test.cgi fails to execute. What is the most likely cause?

Hard
21

Which TWO statements about the /etc/shadow file are true? (Select exactly two.)

Easy
22

A junior admin needs to ensure that the 'apache' user (UID 48) cannot log in via SSH or console. Which command achieves this?

Easy
23

A junior administrator is tasked with setting up SELinux contexts on a Red Hat Enterprise Linux 9 server to allow Apache HTTPD to read and write to a custom directory /var/www/customcontent. The directory already exists and contains several files. The administrator has confirmed that the httpd service is running and SELinux is in enforcing mode. After changing the context to httpd_sys_content_t using chcon, the web server can read files but cannot write to the directory. The administrator needs to fix this without disabling SELinux or changing the mode to permissive. Which of the following is the correct next step?

Easy
24

To allow a user to run a specific program with root privileges without providing the root password, which configuration file should be modified?

Easy
25

Which two statements about SELinux modes are correct? (Choose two.)

Easy
26

You are the system administrator for a small company. A developer, Alice, needs to restart the web server (httpd.service) on server 'web1.example.com' without being prompted for a password. She should also be able to run any command as root on that server, but only from the server itself (not remotely). Currently, Alice can SSH into the server using her SSH key, but when she runs 'sudo systemctl restart httpd', she is prompted for her password. You have verified that Alice is in the 'wheel' group. The sudoers file currently has the line '%wheel ALL=(ALL) ALL'. You want to modify sudoers to satisfy the requirement with minimal privilege. Which action should you take?

Medium
27

Which command checks if a user's password has expired and forces a password change at next login?

Medium
28

A system administrator needs to configure a firewall using firewalld to allow incoming HTTPS traffic and deny incoming SSH traffic from a specific source IP 192.168.1.100. Which two commands should be run? (Choose two.)

Medium
29

A server uses firewalld with the default zone set to 'drop'. SSH is allowed only for the 192.168.1.0/24 subnet via a rich rule in the 'internal' zone. After a reboot, SSH connections from that subnet are refused. What is the most likely cause?

Hard
30

Refer to the exhibit. What is the primary security concern with this sudo configuration?

Medium
31

Refer to the exhibit. An administrator wants to add the HTTP service (port 80) to the internal zone permanently. Which sequence of commands should be used?

Medium
32

Which command sets the password maximum age for user 'bob' to 30 days?

Easy
33

To enforce that user passwords expire every 90 days and users are warned 7 days before expiration, which command sets these policies for user 'john'?

Easy
34

Which three actions enhance security for user accounts on a Red Hat Enterprise Linux system? (Choose three.)

Hard
35

An administrator runs 'getenforce' and sees 'Enforcing'. They then run 'setenforce 0' but SELinux still denies access to a custom application. What is the most likely reason?

Medium
36

Which TWO methods are considered best practices for securing SSH access to a server? (Select exactly two.)

Hard
37

An administrator wants to allow user 'alice' to SSH into the server using key-based authentication only. Which configuration change is required?

Medium
38

A company requires that SSH access from the external network (10.0.1.0/24) only be allowed to port 2222, and all other incoming traffic on the firewall should be dropped. Which firewalld rule should be applied to the external zone?

Hard

Frequently asked questions

What does the Manage security domain cover on the EX200 exam?
You must configure firewalld with firewall-cmd and harden SSH in sshd_config, then verify with firewall-cmd --list-all and ssh. The single most important thing: always use --permanent and --reload together, and restart sshd after any config change.
How many questions are in this domain?
This page lists all 38 Manage security questions in the EX200 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
redhat-rhcsa REDHAT-RHCSA manage security Practice Questions