Courseiva

EX200 Deploy, configure, and maintain systems Practice Question

Which TWO commands can be used to display the current SELinux mode?

⚠ Common exam trap

Red Hat often tests the distinction between commands that *query* state versus those that *modify* state, so candidates may confuse `setenforce` (which changes mode) with `getenforce` (which displays mode).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

getenforce

The `getenforce` command (option C) displays the current SELinux mode as either Enforcing, Permissive, or Disabled. The `sestatus` command (option D) provides a detailed status report including the current mode, the loaded policy, and the mode from the configuration file. Both are standard tools for querying the SELinux operational state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    setenforce

    Why it's wrong here

    setenforce is an administrative utility used to change the running SELinux mode at runtime, passing 0 for permissive or 1 for enforcing; it requires root privileges and immediately alters kernel enforcement, but it never prints the current mode. When invoked without arguments it displays usage information rather than status, and it cannot be used to query whether SELinux is disabled. Because its entire purpose is to mutate policy state, it is not a valid command for merely displaying the current mode.

  • ✗

    ausearch

    Why it's wrong here

    ausearch queries the Linux audit logs, most commonly /var/log/audit/audit.log, filtering events by type, time, user, or to search for specific AVC denial messages tied to SELinux policy decisions. It reads historical records after an event has occurred and can help an administrator understand why a process was denied, but it has no mechanism to report the live SELinux mode. Therefore while it is SELinux-related in the broad sense, it is not a status-display tool.

  • ✓

    getenforce

    Why this is correct

    getenforce is the most direct command for displaying the current SELinux execution mode and prints exactly one of Enforcing, Permissive, or Disabled to standard output. It calls the SELinux library's getenforce function, which reads the kernel-enforced mode, making it convenient for shell scripts and monitoring tools. Unlike sestatus, it provides no policy version, configuration file details, or denial counts, but it is the canonical lightweight way to check the mode alone.

  • ✓

    sestatus

    Why this is correct

    sestatus gives a broader snapshot of SELinux state, showing not only the current mode but also the configured mode from /etc/selinux/config, the policy type (such as targeted), and the loaded policy version. When SELinux is disabled at boot, it reports that status as well, and with the -v flag it can also display file and process contexts. Because it aggregates multiple sources, sestatus is better for initial troubleshooting, but it still ultimately answers the question of current mode, making it a correct choice here.

  • ✗

    semanage

    Why it's wrong here

    semanage is part of the policycoreutils suite and is used to manage persistent SELinux policy configuration, including file contexts, port labels, booleans, and user-to-role mappings. It reads and writes the policy store underneath /etc/selinux rather than querying the kernel's current enforcement state. Since it is designed for modifying policy, not for reporting runtime status, it cannot display the current SELinux mode.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.