EX200 SELinux context Practice Question
Exhibit
$ ls -Z /var/www/cgi-bin/test.cgi system_u:object_r:httpd_sys_content_t:s0
Refer to the exhibit. A CGI script located at /var/www/cgi-bin/test.cgi fails to execute. What is the most likely cause?
⚠ Common exam trap
The pitfall in this question is that examinees often focus on file permissions or script location, overlooking that SELinux contexts (specifically httpd_sys_script_exec_t) are required for CGI execution in Red Hat systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SELinux context should be httpd_sys_script_exec_t.
SELinux contexts control which processes can access files and directories. The CGI script at /var/www/cgi-bin/test.cgi requires the httpd_sys_script_exec_t context to allow the Apache HTTP server (httpd) to execute it. Without this context, SELinux will deny execution even if file permissions and ownership are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The script is in the wrong directory.
Why it's wrong here
The directory /var/www/cgi-bin is the standard CGI directory on Red Hat Enterprise Linux, configured via ScriptAlias /cgi-bin/ /var/www/cgi-bin/ in the Apache configuration. A CGI script placed there is correctly located, and a wrong-path problem would normally produce a 404 Not Found error, not a 500 Internal Server Error. Therefore, the directory is not the cause of the reported failure.
- ✓
The SELinux context should be httpd_sys_script_exec_t.
Why this is correct
SELinux prevents httpd from executing scripts unless the file has the httpd_sys_script_exec_t type, which allows a transition into the httpd_sys_script_t domain when the script runs. If the script retains a generic context such as httpd_sys_content_t or user_home_t, httpd is blocked even when permissions and location are correct, producing a 500 error. Running `restorecon -R /var/www/cgi-bin` or `chcon -t httpd_sys_script_exec_t /var/www/cgi-bin/script.cgi` is the correct fix, not changing permissions.
- ✗
The script is not marked as executable.
Why it's wrong here
Although a CGI script must be executable, simply setting the executable bit does not address the SELinux denial causing this failure. The error log may show 'Permission denied' for both ordinary mode restrictions and SELinux denials, but the executable bit alone cannot override a missing httpd_sys_script_exec_t type. If the problem were only a missing executable mode, `chmod +x` would fix it immediately; the given scenario points directly to a context issue, so this option is not the root cause.
- ✗
The file permissions are incorrect.
Why it's wrong here
Incorrect file permissions could mean wrong ownership or mode bits, but no such problem is indicated in the exhibit; the script is in the standard directory and is likely owned properly. Even if the apache user lacked read or execute access, a RHEL 500 error from a CGI script is typically accompanied by an AVC denial in /var/log/audit/audit.log that cites the missing SELinux type. Fixing permissions alone would not re-contextualize the file, so SELinux corrections are still required, making this option an incorrect explanation of the actual error.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.