CompTIA Linux+ (XK0-006)SecurityEasy
A security administrator is troubleshooting a web application that is being blocked by SELinux even though standard file permissions are correct. The administrator wants to temporarily switch SELinux into a mode that logs violations without blocking them, without rebooting the server. Which command accomplishes this?
- Asestatus --disable
- Bgetenforce permissive
- Csetenforce 0
- Dsemanage permissive -a httpd_t
Show answer & explanationAnswer & explanation
Correct answer: C. setenforce 0
The setenforce command changes the current runtime SELinux mode without a reboot; setenforce 0 sets Permissive mode (log only), while setenforce 1 sets Enforcing mode. The change is not persistent across reboots (that requires editing /etc/selinux/config).
Why the other options are wrong
- A. sestatus only reports status; it has no --disable option to change mode.
- B. getenforce only displays the current mode; it cannot set it.
- D. semanage permissive -a adds a specific domain to permissive list, not a global mode switch.
SELinux Modes
SELinux operates in one of three modes controlling how policy violations are handled at runtime.
- Enforcing: blocks and logs violations
- Permissive: logs only, does not block
- Disabled: SELinux is off entirely
- setenforce changes mode temporarily; /etc/selinux/config changes it permanently
Memory trick: E-P-D: Enforce, Permit(log), Disable — like a bouncer who blocks, warns, or leaves.