EX415 Red Hat Certified Specialist In Security- Linux Practice Questions
Prepare for EX415 with more than an answer.
- 1
You are assigning SELinux user mappings to control user activity. You want to map the Linux user 'consultant_bob' to the SELinux user 'staff_u' so that he has restricted privileges but can use
sudoto gain root access if authorized. Which command accomplishes this?Show answer details
Correct answer: B
The
semanage logincommand maps Linux login users to SELinux users. The-aflag adds a mapping, and-sspecifies the SELinux user (staff_u).staff_uis suitable for non-administrative users who may need to transition to administrative roles via sudo (unlikeuser_uwhich cannot). - 2
You need to configure AIDE to ignore the contents of the
/var/logdirectory but still monitor the attributes (permissions, ownership) of the directory itself. No other selection line in the file covers/var/log. Which rule syntax in/etc/aide.confachieves this?Show answer details
Correct answer: C
AIDE selection lines are regular expressions matched from the start of the full path, because AIDE adds an implicit ^. A regular line such as /var/log PERMS matches /var/log and every path that begins with /var/log, so on its own it would also check every file in the directory. A negative line such as !/var/log/.* excludes every path below /var/log/ but not /var/log itself, because that path has no trailing slash. AIDE checks negative lines last, so a file that matches a negative line is not added even when a regular line also matches it. Together, the two lines put only the directory itself into the database, checked with the PERMS group (permissions, file type, owner, group, ACLs, SELinux context and extended attributes in RHEL's aide.conf). The AIDE manual shows the same pattern: a /var rule followed by !/var/log/.* to ignore the contents of the log directory. The line !/var/log on its own would exclude the directory and everything in it, and !/var/log/.* on its own would exclude the contents but select nothing for the directory.
- 3
When configuring Clevis to bind a LUKS device to a Tang server, you encounter an error stating 'Advertisement is missing'. The Tang server is reachable via ping. What is the most likely cause?
Show answer details
Correct answer: C
Clevis needs to download the advertisement (JSON containing public keys) from the Tang server. If the keys in
/var/db/tangare missing or thetangd.socketis not active/listening on port 80 (or configured port), the advertisement cannot be retrieved. - 4
You are the lead security administrator for a financial institution using Red Hat Enterprise Linux 9. You need to configure Network-Bound Device Encryption (NBDE) to ensure your servers can decrypt their root volumes automatically upon reboot only when they are within the secure corporate network. You have deployed a Tang server at 192.168.10.5. Which command must be executed on the client machine to bind the existing LUKS-encrypted device
/dev/nvme0n1p3to this Tang server using Clevis?Show answer details
Correct answer: B
The
clevis luks bindcommand is used to bind a LUKS device to a pin. In this case, the pin is 'tang' and the configuration JSON string must specify the 'url' of the Tang server. This creates a new keyslot in the LUKS header secured by the Tang server's advertisement. - 5
A security auditor requires a report of all file integrity changes on a production server over the last 24 hours. You have AIDE (Advanced Intrusion Detection Environment) installed and initialized. You run a manual check and find differences. To update the database so that the current state becomes the new baseline for future checks, which sequence of commands should you run?
Show answer details
Correct answer: D
The
aide --updatecommand runs a check and creates a new database file (aide.db.new.gz) that reflects the current system state. To make this the new baseline, you must replace the existing database (aide.db.gz) with this new file. - 6
You are configuring USBGuard on a kiosk system that should only allow a specific USB touch screen and keyboard. You have generated an initial policy allowing connected devices. However, you want to ensure that if the USBGuard daemon stops or crashes, all USB devices are blocked immediately to prevent tampering. Which configuration directive in
/etc/usbguard/usbguard-daemon.confcontrols this behavior?Show answer details
Correct answer: B
The
ImplicitPolicyTargetdirective determines how the daemon treats devices that do not match any rule in the policy. However, regarding the daemon state,PresentControllerPolicyandImplicitPolicyTargetwork together. For fail-safe behavior specifically when the daemon is not running, the kernel enforcing usually keeps the last state, but within the configuration, ensuringImplicitPolicyTarget=blockensures that any device not explicitly allowed is blocked during evaluation.
