CompTIA Linux+ (XK0-006)SecurityMedium

A technician moved a website's files from /tmp/newsite to /var/www/html using the mv command. Standard Linux permissions are correct, but Apache still cannot serve the pages due to SELinux denials in the audit log. Which command should the technician run to fix the file security contexts to match the default policy for that directory?

  1. Achmod -R 755 /var/www/html
  2. Brestorecon -Rv /var/www/html
  3. Cchown -R apache:apache /var/www/html
  4. Dsetsebool -P httpd_enable_homedirs on
Show answer & explanation

Correct answer: B. restorecon -Rv /var/www/html

Because mv preserves the source directory's SELinux context, files moved from /tmp retain the wrong context (typically tmp_t) instead of the httpd_sys_content_t expected in /var/www/html. restorecon -Rv resets the context recursively based on the system's default file context policy.

Why the other options are wrong

  • A. chmod changes standard Unix permissions, not SELinux security contexts.
  • C. chown changes ownership, which does not resolve SELinux context mismatches.
  • D. setsebool toggles booleans for policy behavior, unrelated to fixing incorrect file labels.

SELinux Context Restoration

restorecon resets the SELinux security context of files/directories to the default defined by policy, commonly needed after copying or moving files.

  • mv preserves original context; cp usually gets a new context
  • restorecon -Rv is recursive and verbose
  • chcon changes context manually but is not persistent across restorecon runs
  • semanage fcontext defines persistent custom rules

Memory trick: Moved files carry old labels—restorecon relabels them to fit their new home.

More Security questions