
LPIC-3 Security
Domain 3Objective 2
327.2 Mandatory Access Control (weight: 4) LPIC-3-SECURITY Practice Questions (Page 4)
Part of the Topic 327: Access Control domain, which makes up ~19% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~7–11 in this domain), expect 2–4 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
14concepts
Questions 16–20
- 16
Which command switches an AppArmor profile from complain mode to enforce mode?
Select an answer first - 17
An embedded systems developer is building a device that must enforce mandatory access control with minimal overhead and no dependency on extended attributes. The system uses a custom kernel and needs to label processes and files with simple text labels. Which MAC mechanism is most appropriate?
Select an answer first - 18
A security administrator is migrating a legacy web application to a new RHEL 9 server. The application runs under Apache httpd and needs to write to a custom directory at /srv/webapp/data. After deploying the application, the administrator finds that httpd cannot write to the directory. The administrator checks the SELinux denial log and sees an 'avc: denied { write }' message for httpd_t targeting a file with type httpd_sys_content_t. The administrator wants to fix the issue with the least privilege while keeping SELinux enforcing. What should the administrator do?
Select an answer first - 19
A security administrator is configuring SELinux on a server that runs a custom application. The application runs as a daemon and needs to read files in /var/lib/myapp and write logs to /var/log/myapp. The administrator wants to confine the application with its own domain. What is the first step in creating a custom SELinux policy for this application?
Select an answer first - 20
An administrator is moving a web application from a development server to a production server. The application's files were copied with tar, and the SELinux contexts are now incorrect. The administrator needs to ensure the files have the correct contexts for the production environment. The administrator has already confirmed that the default context for the web root is httpd_sys_content_t. What is the most reliable way to set the correct contexts?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.