EX200 Manage security Practice Question
Which two statements about SELinux modes are correct? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse permissive mode with logging-only behavior, forgetting that permissive mode does not deny actions, while enforcing mode both logs and denies, and that disabling SELinux requires a reboot, not just a runtime change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permissive mode logs violations but does not deny actions.
SELinux permissive mode allows all actions but logs any violations that would have been denied in enforcing mode. Option D is correct because enforcing mode both logs violations and denies actions that violate the SELinux policy, providing full security enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permissive mode denies actions but does not log.
Why it's wrong here
Permissive mode does not deny any operations; instead, it logs actions that would have been denied under enforcing mode and lets them proceed. The statement inverts the behavior: permissive mode precisely avoids denial while recording AVC denials to the audit log. Since it permits rather than denies, claiming it denies without logging is factually incorrect.
- ✓
Permissive mode logs violations but does not deny actions.
Why this is correct
In permissive mode, SELinux policy is not enforced, so processes can perform operations that would normally be prohibited; those violations are recorded as AVC denial messages in the audit log. This behavior is intentional: it allows administrators to observe how SELinux would react without breaking functionality. Therefore, the statement correctly identifies both actions of permissive mode: logging and not denying.
- ✗
Enforcing mode only logs violations but does not deny.
Why it's wrong here
Enforcing mode applies SELinux policy and actively denies any operation that violates the policy, not merely logs it. Saying it 'only logs violations but does not deny' conflates enforcing mode with permissive mode, where denials are logged but not blocked. In enforcing mode, denial and logging occur simultaneously: the operation is rejected and an AVC message is generated.
- ✓
Enforcing mode logs violations and denies actions.
Why this is correct
When SELinux is in enforcing mode, the kernel security server enforces the loaded policy and denies unauthorized operations, generating an AVC denial audit entry for each violation. This is the default operational mode for RHEL, ensuring that policy violations are both recorded and prevented. The statement correctly pairs 'logs' and 'denies' as the two defining characteristics of enforcing mode.
- ✗
Disabled mode completely disables SELinux without requiring a reboot.
Why it's wrong here
To completely disable SELinux, you must either set the kernel boot parameter selinux=0 or change SELINUX=disabled in /etc/selinux/config and reboot; there is no runtime command to disable SELinux entirely. The security server and policy are not initialized during boot if SELinux is disabled, so a reboot is required for the change to take effect. Thus, saying it can be disabled without a reboot is incorrect.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.