EX200 Deploy, configure, and maintain systems Practice Question
Which TWO are correct ways to check the SELinux context of a file named 'test.txt'? (Choose exactly two.)
⚠ Common exam trap
Red Hat often tests the distinction between commands that show SELinux status (`sestatus`, `getenforce`) versus commands that show file-level SELinux context (`ls -Z`, `stat`), trapping candidates who confuse system-wide status with per-file attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ls -Z test.txt
`ls -Z` displays the SELinux security context of files, including user, role, type, and sensitivity level. The `-Z` option is specifically designed to show SELinux context information for files and processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ls -Z test.txt
Why this is correct
ls -Z is correct because the -Z flag, when used with ls, appends a column showing the SELinux security context (user:role:type:level) of the specified path. This output is read directly from the file's inode and provides the per-file label that SELinux uses for access control. It is the standard command for quickly checking a file's context in a directory listing.
- ✗
ls -l test.txt
Why it's wrong here
ls -l is incorrect because the long format displays permission bits, link count, owner, group, file size, and modification time, but it does not include any SELinux metadata. The -l option has no effect on whether contexts appear; to see contexts with ls, the -Z option must be added (e.g., ls -Z test.txt). Thus, ls -l alone cannot reveal the SELinux label.
- ✗
sestatus
Why it's wrong here
sestatus is incorrect because it reports system-wide SELinux state, such as whether SELinux is enabled, the current enforcing or permissive mode, and the configured policy (e.g., targeted, minimum, or mls). It does not accept a filename argument and has no mechanism to inspect the label of a specific object like test.txt. It answers the question 'Is SELinux on and what mode?' not 'What is this file's context?'
- ✗
getenforce
Why it's wrong here
getenforce is incorrect because it only prints the current SELinux mode as one of Enforcing, Permissive, or Disabled. This is a system-wide runtime setting, not a per-file attribute. Because it takes no file operand and returns only the enforcement state, it cannot show the security context of an individual file such as test.txt.
- ✓
stat test.txt
Why this is correct
stat is correct because when SELinux is enabled, the stat command's output includes a dedicated 'Context:' line that presents the SELinux security context for the object. stat gathers this from the inode's extended attributes via the statx() or related system calls, giving a fuller metadata view than ls. Therefore, running stat test.txt is a valid alternative way to verify a file's SELinux label.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.