Courseiva

EX200 Deploy, configure, and maintain systems Practice Question

Which TWO are correct ways to check the SELinux context of a file named 'test.txt'? (Choose exactly two.)

⚠ Common exam trap

Red Hat often tests the distinction between commands that show SELinux status (`sestatus`, `getenforce`) versus commands that show file-level SELinux context (`ls -Z`, `stat`), trapping candidates who confuse system-wide status with per-file attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ls -Z test.txt

`ls -Z` displays the SELinux security context of files, including user, role, type, and sensitivity level. The `-Z` option is specifically designed to show SELinux context information for files and processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ls -Z test.txt

    Why this is correct

    ls -Z is correct because the -Z flag, when used with ls, appends a column showing the SELinux security context (user:role:type:level) of the specified path. This output is read directly from the file's inode and provides the per-file label that SELinux uses for access control. It is the standard command for quickly checking a file's context in a directory listing.

  • ✗

    ls -l test.txt

    Why it's wrong here

    ls -l is incorrect because the long format displays permission bits, link count, owner, group, file size, and modification time, but it does not include any SELinux metadata. The -l option has no effect on whether contexts appear; to see contexts with ls, the -Z option must be added (e.g., ls -Z test.txt). Thus, ls -l alone cannot reveal the SELinux label.

  • ✗

    sestatus

    Why it's wrong here

    sestatus is incorrect because it reports system-wide SELinux state, such as whether SELinux is enabled, the current enforcing or permissive mode, and the configured policy (e.g., targeted, minimum, or mls). It does not accept a filename argument and has no mechanism to inspect the label of a specific object like test.txt. It answers the question 'Is SELinux on and what mode?' not 'What is this file's context?'

  • ✗

    getenforce

    Why it's wrong here

    getenforce is incorrect because it only prints the current SELinux mode as one of Enforcing, Permissive, or Disabled. This is a system-wide runtime setting, not a per-file attribute. Because it takes no file operand and returns only the enforcement state, it cannot show the security context of an individual file such as test.txt.

  • ✓

    stat test.txt

    Why this is correct

    stat is correct because when SELinux is enabled, the stat command's output includes a dedicated 'Context:' line that presents the SELinux security context for the object. stat gathers this from the inode's extended attributes via the statx() or related system calls, giving a fuller metadata view than ls. Therefore, running stat test.txt is a valid alternative way to verify a file's SELinux label.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.