CompTIA Linux+ (XK0-006)SecurityEasy

A security administrator is troubleshooting a web application that is being blocked by SELinux even though standard file permissions are correct. The administrator wants to temporarily switch SELinux into a mode that logs violations without blocking them, without rebooting the server. Which command accomplishes this?

  1. Asestatus --disable
  2. Bgetenforce permissive
  3. Csetenforce 0
  4. Dsemanage permissive -a httpd_t
Show answer & explanation

Correct answer: C. setenforce 0

The setenforce command changes the current runtime SELinux mode without a reboot; setenforce 0 sets Permissive mode (log only), while setenforce 1 sets Enforcing mode. The change is not persistent across reboots (that requires editing /etc/selinux/config).

Why the other options are wrong

  • A. sestatus only reports status; it has no --disable option to change mode.
  • B. getenforce only displays the current mode; it cannot set it.
  • D. semanage permissive -a adds a specific domain to permissive list, not a global mode switch.

SELinux Modes

SELinux operates in one of three modes controlling how policy violations are handled at runtime.

  • Enforcing: blocks and logs violations
  • Permissive: logs only, does not block
  • Disabled: SELinux is off entirely
  • setenforce changes mode temporarily; /etc/selinux/config changes it permanently

Memory trick: E-P-D: Enforce, Permit(log), Disable — like a bouncer who blocks, warns, or leaves.

More Security questions