certslothcertsloth
EX200/Topic 02

Red Hat / Associate

Users, Permissions and SELinux

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Identity, mode bits and labels must all agree.

Must remember

  • useradd, usermod, userdel, groupadd and groupmod manage local accounts. id USER verifies identity and supplementary groups; getent passwd USER respects configured identity sources. Use usermod -aG to append group membership; omitting -a can replace existing supplementary groups.
  • passwd changes passwords and chage -l USER inspects aging. Locking a password does not necessarily revoke SSH keys or existing sessions. Use sudo for delegated privilege; edit sudoers through visudo to check syntax.
  • For a regular file, r/w/x mean read/change/execute. For a directory, they mean list names/change entries/traverse. Deleting a file depends mainly on its parent directory permissions, with sticky-bit rules when present.
  • chmod 640 file gives owner rw, group r, others none. chown user:group file changes ownership. Setgid on a shared directory helps new files inherit its group; sticky limits removal of other users' entries. umask removes default permission bits; it does not add execute permission to ordinary newly created files.
  • SELinux adds mandatory policy checks beyond Unix permissions. Enforcing blocks prohibited actions; permissive records denials without enforcing them. Inspect getenforce, ls -Z, ps -eZ and audit messages.
  • restorecon restores configured labels. semanage fcontext defines persistent path-label rules; chcon alone may be overwritten by relabeling. semanage port maps a nonstandard service port to its allowed type. getsebool inspects booleans; setsebool -P persists a supported policy toggle.

Practical drill: create a shared directory for a group, then explain why a web service still needs the correct SELinux type even when Unix permissions allow reading.

Choose under exam pressure

Requirement Choice and reason
Group-shared directory Correct group ownership, directory permissions and setgid where needed.
Service denied despite mode bits Inspect SELinux labels and AVC denials.
Permanent label for a custom web path Define an fcontext rule, then apply restorecon.

Traps

  • Do not solve a labeling error by disabling SELinux.
  • chmod 777 does not bypass SELinux and usually grants excessive access.

Active recall

1. Which permission permits traversing a directory?

Execute; reading lists names and writing changes entries.

2. Why use usermod -aG?

To append supplementary membership without dropping other groups.

3. What persists a custom file-context rule?

semanage fcontext followed by restorecon applies a persistent label mapping.

4. Why can a password-locked user still authenticate?

Other credentials such as authorized SSH keys may still be accepted.

5. What must change for a service to use an unusual SELinux-controlled port?

The port’s SELinux type mapping, as well as the service and firewall configuration.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.