
F5Certified Administrator NGINX - Troubleshooting
Domain 2Objective 8
Describe Basic SELinux Use Cases F5N4 Practice Questions (Page 1)
Part of the Troubleshoot basic use cases domain, which makes up ~60% of our current practice bank. F5 does not publish an official question count, but from its 30-minute exam (~10–20 total, ~6–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
Questions 1–5
- 1
A developer created a new directory /srv/nginx-content and moved website files into it. NGINX is configured with root /srv/nginx-content;. The site returns 403 Forbidden. The audit log shows: 'avc: denied { getattr } for pid=1234 comm="nginx" name="/" dev="dm-0" scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:default_t:s0 tclass=dir'. What is the correct fix?
Select an answer first - 2
An NGINX server on RHEL 9 was working normally until a security patch was applied. Now, when clients connect to the site, they receive a 502 Bad Gateway error. The NGINX error log shows 'connect() to 127.0.0.1:8080 failed (13: Permission denied)'. The upstream application on port 8080 is confirmed listening and reachable via curl from the shell. What is the most likely cause and the first diagnostic step?
Select an answer first - 3
A security audit requires documentation of the SELinux context of the NGINX binary and its configuration files. Which command provides the context for the NGINX binary, and what type should it have on a standard RHEL system?
Select an answer first - 4
An NGINX server is failing to proxy requests to a backend on port 8443. The audit log shows: 'avc: denied { name_connect } for pid=1234 comm="nginx" dest=8443 scontext=system_u:system_r:httpd_t:s0 tcontext=system_u:object_r:http_cache_port_t:s0 tclass=tcp_socket'. The admin has already enabled httpd_can_network_connect, but the denial persists. What is the most likely reason and the correct next step?
Select an answer first - 5
An administrator needs to allow NGINX to make outbound network connections to a backend server. What is the recommended method to resolve this SELinux denial?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “F5N4” is a trademark of its owner, used for identification only.