CompTIA Linux+ (XK0-006)TroubleshootingHard
A web server's content directory was recently restored from an archive using `tar`. Users receive HTTP 403 Forbidden errors even though `ls -l /var/www/html` shows correct ownership (apache:apache) and permissions (644 for files, 755 for directories). SELinux is enabled and set to Enforcing. Which command most directly resolves this issue?
- Achmod -R 755 /var/www/html
- Bchown -R apache:apache /var/www/html
- Crestorecon -Rv /var/www/html
- Dsetenforce 0
Show answer & explanationAnswer & explanation
Correct answer: C. restorecon -Rv /var/www/html
When files are restored via tar (or copied/moved incorrectly), they often inherit the SELinux context of their source location rather than the correct context for /var/www/html (typically httpd_sys_content_t). restorecon -Rv relabels the files and directories recursively based on the system's SELinux policy, resolving the 403 error without needing to disable SELinux enforcement.
Why the other options are wrong
- A. chmod changes standard Unix permissions, which the scenario states are already correct.
- B. chown changes ownership, which the scenario states is already correct.
- D. Disabling SELinux enforcement is a security risk and only masks the underlying context problem.
SELinux Context Restoration
restorecon relabels files and directories to match the SELinux context defined by the active policy, fixing access denials caused by mislabeled files (e.g., after copy/restore operations).
- Check current context: ls -Z
- Common web content context: httpd_sys_content_t
- Check denials in /var/log/audit/audit.log via ausearch or sealert
Memory trick: Unix permissions say yes, but SELinux context says no — restorecon fixes the label.