EX415 Sample Questions & Answers
Free Red Hat Certified Specialist In Security- Linux practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full EX415 simulator →Showing 6 of 12 free samples.
- Question 1Beginner
Configure SELinux · Analyze and correct existing SELinux configurations
While investigating a permission issue on a web server, you notice that the Apache service cannot read files in a custom directory
/srv/www/html. You suspect an SELinux context mismatch. You decide to compare the file contexts of the working default directory/var/www/htmlwith your custom directory. Which command should you use to view the security context of the files?Show answer & explanation
Correct answer: C
The
ls -Zcommand displays the SELinux security context (user:role:type:level) of files and directories, allowing you to compare the contexts between the two locations. - Question 2Intermediate
Configure system auditing · Write rules to log auditable events
You need to configure the Linux Audit system to monitor all write access and attribute changes to the
/etc/passwdfile by any user. The rule must add a key named 'identity_change' to the log entries. Which audit rule is correct?Show answer & explanation
Correct answer: D
The
-wflag sets a file system watch. The-pflag specifies permissions to watch for: 'w' (write) and 'a' (attribute change). The-kflag assigns a key to the rule for searching logs later. - Question 3Advanced
Configure Ansible Automation Platform · Implement access controls for automation controller
Your organization uses Red Hat Ansible Automation Platform. You need to ensure that a junior administrator, 'UserA', can only run playbooks against a specific set of development servers defined in an inventory named 'DevInventory'. They should not see or access the 'ProdInventory'. Which combination of permissions must be assigned to UserA in the Automation Controller?
Show answer & explanation
Correct answer: C
To run a job, a user needs 'Execute' permission on the Job Template. The Job Template is linked to an Inventory. To use that inventory, the user specifically needs the 'Use' role on that Inventory object. They do not need 'Admin' or 'Read' on other inventories they shouldn't access.
- Question 4IntermediateSelect 2
Manage system login security using pluggable authentication modules (PAM) · Configure password quality requirements
You are implementing a password policy using
pam_pwquality. You need to ensure that users cannot reuse their last 5 passwords and that the new password must differ from the old one by at least 3 characters. Which two parameters should you configure in/etc/security/pwquality.confor the appropriatepam_pwquality.soline? (Select TWO)Show answer & explanation
Correct answers: B, D
To prevent reuse of the last 5 passwords, the
remember=5option must be used withpam_pwhistory.so(usually insystem-authandpassword-auth). Thedifok=3parameter inpwquality.confhandles the character difference requirement.The
difokparameter specifies the number of characters in the new password that must not be present in the old password. - Question 5Beginner
Configure system auditing · Enable prepackaged rules
You have customized the system audit rules in
/etc/audit/rules.d/99-custom.rules. You want to load these rules immediately without rebooting the system. Which command should you run to load the rules from the configuration files into the kernel?Show answer & explanation
Correct answer: D
The
augenrulesscript merges all files from/etc/audit/rules.d/into/etc/audit/audit.rules. The--loadargument then loads these rules into the kernel immediately. - Question 6Advanced
Enforce security compliance using OpenSCAP · Generate and apply a playbook from customized XML for remediation of inventory hosts
Case Study:
Company Background
TechSafe Solutions is deploying a new secure logging infrastructure. All servers run Red Hat Enterprise Linux 9.Requirement
You need to configure OpenSCAP to scan systems nightly. The security policy requires that all systems adhere to the PCI-DSS profile. If a system fails the scan, it should automatically attempt to remediate using an Ansible Playbook generated from the scan results.Current Situation
You have installedopenscap-scannerandscap-security-guide. You have performed a manual scan usingoscapand verified the failures.Question
Which command sequence best generates a remediation Ansible playbook based strictly on the failed results of a previous scan stored inresults.xml?Show answer & explanation
Correct answer: C
The
oscap xccdf generate fixcommand is used to generate remediation scripts. Specifying--fix-type ansiblegenerates an Ansible playbook. Using the input fileresults.xml(which contains TestResults) ensures the playbook only targets the rules that failed in that specific scan, rather than all rules in the profile.
Ready for the real thing?
The full EX415 simulator has every exam-style question, timed mode, and instant scoring.