---
tags:
- security
- l1
- flashcard-deck
- selinux
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [SELinux & AppArmor](../../../../library/portal/topics.md) | **Domain:** Security
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
selinux/a1c2d3e4f5b6	selinux	easy	selinux, modes	What are the three SELinux modes and what does each do?	Enforcing: blocks and logs policy violations (production mode). Permissive: logs violations but does not block (debugging mode). Disabled: no enforcement or logging (never use in production).\n\nRemember: "SELinux = mandatory access control on top of DAC." Even root can be restricted by SELinux policy.\n\nFun fact: SELinux was developed by the NSA and contributed to the Linux kernel.	training/library/topics/selinux-apparmor/primer.md
selinux/b2d3e4f5a6c7	selinux	easy	selinux, commands	How do you check the current SELinux mode?	Run getenforce for the simple mode name, or sestatus for detailed status including policy type and mode.\n\nRemember: "Enforcing = blocks, Permissive = logs, Disabled = off." Check with getenforce. Change temporarily with setenforce 0|1.\n\nGotcha: Switching from Disabled to Enforcing requires a full relabel: touch /.autorelabel && reboot.	training/library/topics/selinux-apparmor/primer.md
selinux/c3e4f5a6b7d8	selinux	easy	selinux, contexts	What are the four fields of an SELinux security context?	user:role:type:level. Example: system_u:system_r:httpd_t:s0. The type field (e.g., httpd_t) is where 95% of policy decisions happen.\n\nRemember: "SELinux labels have four parts: user:role:type:level." The type (third field) is what matters most for day-to-day troubleshooting.\n\nExample: ls -Z /var/www shows httpd_sys_content_t — the type Apache is allowed to read.	training/library/topics/selinux-apparmor/primer.md
selinux/d4f5a6b7c8e9	selinux	medium	selinux, booleans	What are SELinux booleans and how do you enable one persistently?	Booleans are toggle switches that enable/disable specific policy behaviors without writing custom policy. Enable persistently with: setsebool -P httpd_can_network_connect on (the -P flag persists across reboots).\n\nExample: chcon -t httpd_sys_content_t /var/www/mysite/index.html temporarily fixes the label. restorecon -Rv /var/www/ applies the permanent policy.\n\nRemember: "chcon = temporary, restorecon = permanent. Always prefer restorecon."	training/library/topics/selinux-apparmor/primer.md
selinux/e5a6b7c8d9f0	selinux	medium	selinux, restorecon, file-contexts	Why is "semanage fcontext + restorecon" preferred over chcon for fixing file labels?	chcon sets a temporary label that does not survive a restorecon or filesystem relabel. semanage fcontext creates a persistent rule in the policy database, and restorecon applies it. The persistent rule ensures labels are correct after any relabeling event.\n\nExample: setsebool -P httpd_can_network_connect on permanently allows Apache to make network connections.\n\nRemember: "Booleans = SELinux feature toggles. -P = persistent across reboots."	training/library/topics/selinux-apparmor/primer.md
selinux/f6b7c8d9e0a1	selinux	medium	selinux, audit2allow, troubleshooting	How do you use audit2allow to diagnose and fix SELinux denials?	1) Find denials: ausearch -m AVC -ts recent. \n2) Generate a policy module: ausearch -m AVC -ts recent | audit2allow -M myfix. \n3) Review the .te file to verify it is not overly permissive. \n4) Install if appropriate: semodule -i myfix.pp. Never blindly apply without reviewing.	training/library/topics/selinux-apparmor/primer.md
selinux/a7c8d9e0f1b2	selinux	medium	selinux, containers	How does SELinux interact with container volume mounts?	Containers are auto-labeled with container_t. Volume mounts need the :Z (private label) or :z (shared label) suffix, e.g., podman run -v /data:/data:Z myimage. Without it, SELinux blocks the container from accessing the volume.	training/library/topics/selinux-apparmor/primer.md
selinux/b8d9e0f1a2c3	selinux	hard	selinux, apparmor, comparison	What are the key differences between SELinux and AppArmor?	SELinux uses label-based enforcement (labels survive file moves/renames) and ships with RHEL/CentOS. AppArmor uses path-based enforcement (simpler to reason about) and ships with Ubuntu/SUSE. SELinux supports MLS and has a steeper learning curve. AppArmor has no multi-level security.	training/library/topics/selinux-apparmor/primer.md
selinux/c9e0f1a2b3d4	selinux	hard	selinux, apparmor, profiles	How do you create and enforce an AppArmor profile for a new application?	Use aa-genprof /usr/sbin/myapp to generate a skeleton profile interactively. Run the app in complain mode to log all access patterns, then use aa-logprof to refine the profile from logs. Switch to enforce mode with aa-enforce /etc/apparmor.d/usr.sbin.myapp.	training/library/topics/selinux-apparmor/primer.md
selinux/d0f1a2b3c4e5	selinux	hard	selinux, ports, policy	How do you allow a service to bind to a non-standard port in SELinux?	Use semanage port to add the port to the appropriate type. \nExample: semanage port -a -t http_port_t -p tcp 8090 allows httpd_t processes to bind to port 8090. Without this, SELinux blocks the bind even if the firewall allows it.	training/library/topics/selinux-apparmor/primer.md
selinux/e1a2b3c4d5f6	selinux	easy	selinux, enforcing, permissive	How do you switch between SELinux enforcing and permissive modes and when should you?	Temporarily: setenforce 0 (permissive) or setenforce 1 (enforcing) — does not survive reboot.\nPermanently: edit /etc/selinux/config and set SELINUX=enforcing or SELINUX=permissive.\nUse permissive only for debugging — it logs denials without blocking. Switch to permissive when diagnosing AVC denials, collect the denials, create policy fixes, then switch back to enforcing. Never run permissive in production long-term.	
selinux/f2b3c4d5e6a7	selinux	medium	selinux, booleans, common	What are the most commonly needed SELinux booleans for web servers?	httpd_can_network_connect: allow HTTPD to make outbound network connections (needed for reverse proxy to backends).\nhttpd_can_network_connect_db: allow HTTPD to connect to database ports.\nhttpd_use_nfs: allow HTTPD to serve files from NFS mounts.\nhttpd_enable_homedirs: allow HTTPD to serve user home directories.\nList all booleans: getsebool -a | grep httpd. Always use setsebool -P for persistent changes.	
selinux/a3c4d5e6f7b8	selinux	medium	selinux, context-labels, files	How do SELinux context labels work for files and why do they matter?	Every file has an SELinux context (ls -Z shows it). Web content needs httpd_sys_content_t, writable web dirs need httpd_sys_rw_content_t. When you copy files, the destination context is inherited from the parent directory. When you move files (mv), the original context is preserved — this is a common source of denials. Fix with restorecon -Rv /path to reset labels to the policy default for that location.	
selinux/b4d5e6f7a8c9	selinux	hard	selinux, audit2allow, workflow	What is the proper workflow for creating a custom SELinux policy module?	1) Set the domain to permissive (semanage permissive -a httpd_t) to collect all denials without blocking.\n2) Exercise all application functionality to trigger denials.\n3) Collect denials: ausearch -m AVC -ts recent > denials.txt.\n4) Generate policy: audit2allow -M mypolicy < denials.txt.\n5) Review the .te file — remove overly broad rules.\n6) Install: semodule -i mypolicy.pp.\n7) Remove permissive: semanage permissive -d httpd_t.\n8) Test in enforcing mode.	
selinux/c5e6f7a8b9d0	selinux	medium	selinux, troubleshooting, avc	How do you troubleshoot SELinux AVC denial messages?	1) Find the denial: ausearch -m AVC -ts recent or journalctl -t setroubleshoot.\n2) Read the sealert suggestion: sealert -l <alert-id> (if setroubleshoot is installed).\n3) Check if a boolean fixes it: sesearch --allow -s httpd_t -t target_type.\n4) Verify file contexts: ls -Z and compare against policy (matchpathcon path).\n5) Try restorecon first (most common fix), then booleans, then custom policy as a last resort.	
selinux/d6f7a8b9c0e1	selinux	hard	selinux, semanage, custom-policies	How do you use semanage to customize SELinux policy for non-standard configurations?	semanage fcontext: define file context rules for custom paths (e.g., semanage fcontext -a -t httpd_sys_content_t "/srv/myapp(/.*)?" then restorecon -Rv /srv/myapp).\nsemanage port: allow services on non-standard ports.\nsemanage login: map Linux users to SELinux users.\nsemanage boolean: manage persistent booleans.\nAll semanage changes persist across policy updates and relabels, unlike chcon which is temporary.	
selinux/e7a8b9c0d1f2	selinux	medium	selinux, containers, podman	How does SELinux protect containers and what are the key considerations?	Containers run with the container_t type, which restricts access to only container-labeled resources. Each container gets a unique MCS (Multi-Category Security) label, preventing one container from accessing another's files even if they share a volume. Key considerations: use :Z (private) or :z (shared) suffixes on volume mounts, Podman supports full SELinux integration by default, and Docker requires --security-opt label=type:container_t for custom types.	
selinux/9d5d96a93908	selinux	hard	selinux, mcs, containers, isolation	How does SELinux Multi-Category Security (MCS) isolate containers from each other?	Each container gets a unique MCS label (e.g., s0:c123,c456). Even though all containers run as svirt_lxc_net_t, the unique category pair prevents one container from accessing another's files or processes. Podman and CRI-O assign MCS labels automatically; Docker requires --security-opt.	training/library/topics/selinux-apparmor/primer.md
selinux/2bc9f947047f	selinux	medium	selinux, systemd, confinement	How do you confine a custom systemd service with SELinux?	Create a custom policy module: use audit2allow -M myapp from AVC denials in permissive mode, or write a .te policy file defining a new type (myapp_t) with required permissions. Install with semodule -i, set the binary's file context, and switch to enforcing. Test thoroughly in permissive first.	training/library/topics/selinux-apparmor/primer.md
selinux/19bb9b6bd8ca	selinux	medium	selinux, chcon, semanage, persistence	Why does chcon not survive a relabel while semanage fcontext does?	chcon sets the SELinux context directly on the file's extended attributes but does not update the file_contexts policy database. When restorecon runs (or a full relabel), it resets contexts to what the policy says. semanage fcontext adds a persistent rule to the policy, so restorecon applies the correct context.	training/library/topics/selinux-apparmor/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [RHCE (EX294) Exam Preparation](../../../../library/topics/rhce/index.md) (Topic Pack, L2) — SELinux & AppArmor
- [SELinux & AppArmor](../../../../library/topics/selinux-apparmor/index.md) (Topic Pack, L2) — SELinux & AppArmor

<!-- wiki:related:end -->
