Courseiva
Manage security →hardMultiple Choice

EX200 Manage security Practice Question

Network Topology
-rw-rrls -Z /var/www/html/index.html output:

Refer to the exhibit. A web server is serving content from /var/www/html. SELinux is in enforcing mode. The web client reports 'Forbidden'. What is the most likely cause?

⚠ Common exam trap

A common pitfall in Red Hat RHCSA is assuming that file permissions alone cause 'Forbidden' errors, but with SELinux enforcing, incorrect context (e.g., httpd_user_content_t instead of httpd_sys_content_t) is the primary cause. Candidates must remember that SELinux overrides DAC permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The directory /var/www/html may have incorrect context or permissions preventing Apache from listing files.

The most likely cause of a 'Forbidden' error when SELinux is enforcing is that the directory or file lacks the correct SELinux context (e.g., httpd_sys_content_t) or the permissions do not allow the Apache user (apache) to read or traverse the directory. Even if file permissions are 644, SELinux can block access if the context is wrong, such as being set to default_t or user_home_t. The error indicates Apache cannot access the content, which is typically resolved by restoring the correct context with restorecon or setting it with chcon.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The file is owned by root, and Apache runs as apache user, so it cannot read.

    Why it's wrong here

    In Linux, access to a file is determined by the permission bits and ACLs, not by which user owns the file. The apache user falls into the 'other' class for a file owned by root; as long as the 'other' permissions include read (r), Apache can read it. A 644 file gives r-- to others, so root ownership alone never blocks Apache.

  • ✓

    The directory /var/www/html may have incorrect context or permissions preventing Apache from listing files.

    Why this is correct

    The directory /var/www/html must be both readable and executable (searchable) for Apache to enter it and list or serve files; if it is 700 root:root or has a restrictive context, Apache is denied. SELinux also requires the httpd_sys_content_t type on this directory; if it was incorrectly relabeled, httpd cannot access it. This is the classic cause of a 403 'Forbidden' error even when the file itself is world-readable.

  • ✗

    The file permissions are 644, which restricts access.

    Why it's wrong here

    Mode 644 (rw-r--r--) gives every other user, including the apache user, read permission on the file. It does not restrict access because the final 'r' applies to the 'others' class, and the Apache process is not root nor in the file's group. If this file caused an error, it would not be due to 644 but due to something like directory permissions or SELinux.

  • ✗

    The file has an incorrect SELinux context; it should be httpd_user_content_t.

    Why it's wrong here

    The SELinux type httpd_sys_content_t is the correct default for web content under /var/www/html; httpd_t is allowed to read files with that type. In contrast, httpd_user_content_t is designed for web content in user home directories (e.g., ~/public_html) and is gated by the httpd_enable_home_dirs boolean. Choosing that type for /var/www/html would actually break access, because httpd is not permitted to read user_home_t-like content in that location without additional settings.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.