Courseiva

EX200 · topic practice

Manage security practice questions

This domain covers host-based security on RHEL: configuring firewalld zones, services, ports, and rich rules with firewall-cmd, hardening sshd via /etc/ssh/sshd_config, and managing SELinux modes and file contexts with getenforce, setenforce, semanage, and restorecon. EX200 tests these through hands-on tasks you perform on a live system, not multiple-choice recall.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage security

What the exam tests

What to know about Manage security

You must configure firewalld with firewall-cmd and harden SSH in sshd_config, then verify with firewall-cmd --list-all and ssh. The single most important thing: always use --permanent and --reload together, and restart sshd after any config change.

Opening or restricting ports and services with firewall-cmd --permanent plus --reload, and assigning interfaces to zones

Hardening sshd_config: disabling root login, password authentication, and restricting users or groups

Creating rich rules to limit source networks to specific ports, such as allowing 10.0.1.0/24 to port 2222

Managing SELinux with getenforce, setenforce, semanage fcontext, and restorecon to fix denied access

Watch out for

Common Manage security exam traps

  • ▸Adding firewall rules without --permanent, so changes vanish after reload or reboot; or forgetting --reload so the running config never updates.
  • ▸Editing sshd_config but not restarting sshd, or setting PermitRootLogin and PasswordAuthentication incorrectly so key-only login still fails.
  • ▸Changing SELinux to permissive instead of fixing the file context with semanage fcontext and restorecon, which loses points on grading.

Practice set

Manage security questions

20 questions · select your answer, then reveal the explanation

Which THREE factors determine whether a local user can SSH into a Red Hat Enterprise Linux 9 system? (Choose three.)

Refer to the exhibit. A web server (httpd) is unable to serve files from a user's home directory. What is the most appropriate single command to resolve the issue?

Exhibit

Refer to the exhibit.

```
# ausearch -m avc -ts recent
----
time->Thu Mar 14 10:15:22 2024
type=AVC msg=audit(1710418522.123:456): avc:  denied  { read } for  pid=1234 comm="httpd" name="index.html" dev=sda1 ino=5678 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:user_home_t:s0 tclass=file
```

A sysadmin wants to allow user 'alice' to run all commands as root via sudo. Which line should be added to /etc/sudoers?

A user reports that SSH key-based authentication fails, but password authentication works. The admin checks /etc/ssh/sshd_config: PubkeyAuthentication yes, PasswordAuthentication no (contrary to the report). Which is the most likely reason key-based auth fails?

Question 5mediummultiple choice
Read the full Manage security explanation →

Refer to the exhibit. A host in the 192.168.1.0/24 network is unable to access a web service running on this server on port 8080. What is the most likely reason?

Network Topology
firewall-cmdzone=internallist-all output:internal (active)target: defaulticmp-block-inversion: nointerfaces: eth1sources:services: dhcpv6-client sshports:protocols:masquerade: noforward-ports:source-ports:icmp-blocks:rich rules:

An auditor requires that all failed SSH login attempts be logged to a separate file /var/log/ssh_failures. Which configuration is needed in /etc/rsyslog.conf or /etc/rsyslog.d/?

Which TWO of the following are valid methods to enforce password complexity requirements on a Red Hat Enterprise Linux 9 system?

Question 8hardmultiple choice
Review the full routing breakdown →

A Red Hat Enterprise Linux 9 system is configured as a router between an internal network (10.0.1.0/24) and a DMZ network (10.0.2.0/24). IP forwarding is enabled, and firewalld is active. The internal interface (eth0) is assigned to the 'internal' firewall zone, and the DMZ interface (eth1) is assigned to the 'dmz' zone. The requirement is that hosts on the internal network should be able to initiate connections to hosts in the DMZ, but the DMZ should not be able to initiate connections to the internal network. The administrator finds that traffic from internal to DMZ is being blocked. The internal zone has 'masquerade' enabled, and the dmz zone has no special settings. What is the most likely cause of the blocked traffic?

A systems administrator needs to list all currently defined firewall rules in firewalld, including rules for all zones. Which TWO commands can be used to accomplish this? (Choose exactly two.)

Question 10hardmultiple choice
Read the full Manage security explanation →

A systems administrator is managing a RHEL 9 server that hosts a custom web application on Apache. The application writes log files to /var/log/myapp/ and runs as the apache user. The administrator has set the directory permissions to 755 and ownership to apache:apache. SELinux is in enforcing mode. Despite these settings, the application fails to write logs. The audit log contains multiple AVC denials with the message 'avc: denied { write } for pid=1234 comm="httpd" name="myapp.log" dev="dm-0" ino=5678 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:var_log_t:s0 tclass=file'. The administrator has verified that the file exists and that SElinux booleans related to httpd are at their default values. Which of the following steps should the administrator take to resolve the issue while maintaining security?

Question 11mediummultiple choice
Read the full Manage security explanation →

A junior administrator on a RHEL 9 server runs `ls -Z /srv/reports/quarterly.xlsx` and sees the type `default_t`. The file is served by an httpd virtual host rooted at /srv/reports, and every request returns HTTP 403. The administrator has already confirmed the file permissions are 0644 and the SELinux policy is enforcing. Which command most directly resolves the denial without disabling SELinux?

Question 12easymultiple choice
Read the full Manage security explanation →

A junior admin needs to ensure that the 'apache' user (UID 48) cannot log in via SSH or console. Which command achieves this?

Question 13mediummultiple choice
Read the full Manage security explanation →

An administrator runs 'getenforce' and sees 'Enforcing'. They then run 'setenforce 0' but SELinux still denies access to a custom application. What is the most likely reason?

Question 14hardmultiple choice
Read the full Manage security explanation →

A system administrator wants to allow user 'jdoe' to execute any command as root via sudo without being prompted for a password, but only from the host 'client1.example.com'. Which sudoers rule achieves this?

Question 15mediummultiple choice
Read the full Manage security explanation →

A server's firewall is managed by firewalld. The admin adds a rule to allow HTTPS traffic to the public zone, but clients still cannot connect. What is the most likely cause?

Which TWO commands can be used to display SELinux contexts of files? (Choose two.)

Question 17mediummultiple choice
Read the full Manage security explanation →

You are the system administrator for a small company. A developer, Alice, needs to restart the web server (httpd.service) on server 'web1.example.com' without being prompted for a password. She should also be able to run any command as root on that server, but only from the server itself (not remotely). Currently, Alice can SSH into the server using her SSH key, but when she runs 'sudo systemctl restart httpd', she is prompted for her password. You have verified that Alice is in the 'wheel' group. The sudoers file currently has the line '%wheel ALL=(ALL) ALL'. You want to modify sudoers to satisfy the requirement with minimal privilege. Which action should you take?

A system administrator needs to configure a firewall using firewalld to allow incoming HTTPS traffic and deny incoming SSH traffic from a specific source IP 192.168.1.100. Which two commands should be run? (Choose two.)

Question 19easymultiple choice
Read the full Manage security explanation →

A junior administrator is tasked with setting up SELinux contexts on a Red Hat Enterprise Linux 9 server to allow Apache HTTPD to read and write to a custom directory /var/www/customcontent. The directory already exists and contains several files. The administrator has confirmed that the httpd service is running and SELinux is in enforcing mode. After changing the context to httpd_sys_content_t using chcon, the web server can read files but cannot write to the directory. The administrator needs to fix this without disabling SELinux or changing the mode to permissive. Which of the following is the correct next step?

Order the steps to configure firewall rules to allow HTTP and HTTPS traffic using firewalld.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage security sessions

Start a Manage security only practice session

Every question in these sessions is drawn from the Manage security domain — nothing else.

Related practice questions

Related EX200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the EX200 exam test about Manage security?
You must configure firewalld with firewall-cmd and harden SSH in sshd_config, then verify with firewall-cmd --list-all and ssh. The single most important thing: always use --permanent and --reload together, and restart sshd after any config change.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage security questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other EX200 topics?
Use the topic links above to move to related areas, or go back to the EX200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the EX200 exam covers. They are not copied from any real exam or dump site.