EX415 Sample Questions

EX415 Sample Questions & Answers

Free Red Hat Certified Specialist In Security- Linux practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full EX415 simulator →

Free EX415 Sample Questions with Answers

Real questions from the Red Hat Certified Specialist In Security- Linux practice test — answers and explanations included. Showing 6 of 12 free samples.

  1. Question 1Beginner

    Configure SELinux · Analyze and correct existing SELinux configurations

    While investigating a permission issue on a web server, you notice that the Apache service cannot read files in a custom directory /srv/www/html. You suspect an SELinux context mismatch. You decide to compare the file contexts of the working default directory /var/www/html with your custom directory. Which command should you use to view the security context of the files?

    Show answer & explanation

    Correct answer: A

    The ls -Z command displays the SELinux security context (user:role:type:level) of files and directories, allowing you to compare the contexts between the two locations.

  2. Question 2Intermediate

    Configure system auditing · Write rules to log auditable events

    You need to configure the Linux Audit system to monitor all write access and attribute changes to the /etc/passwd file by any user. The rule must add a key named 'identity_change' to the log entries. Which audit rule is correct?

    Show answer & explanation

    Correct answer: A

    The -w flag sets a file system watch. The -p flag specifies permissions to watch for: 'w' (write) and 'a' (attribute change). The -k flag assigns a key to the rule for searching logs later.

  3. Question 3Advanced

    Configure Ansible Automation Platform · Implement access controls for automation controller

    Your organization uses Red Hat Ansible Automation Platform. You need to ensure that a junior administrator, 'UserA', can only run playbooks against a specific set of development servers defined in an inventory named 'DevInventory'. They should not see or access the 'ProdInventory'. Which combination of permissions must be assigned to UserA in the Automation Controller?

    Show answer & explanation

    Correct answer: A

    To run a job, a user needs 'Execute' permission on the Job Template. The Job Template is linked to an Inventory. To use that inventory, the user specifically needs the 'Use' role on that Inventory object. They do not need 'Admin' or 'Read' on other inventories they shouldn't access.

  4. Question 4IntermediateSelect 2

    Manage system login security using pluggable authentication modules (PAM) · Configure password quality requirements

    You are implementing a password policy using pam_pwquality. You need to ensure that users cannot reuse their last 5 passwords and that the new password must differ from the old one by at least 3 characters. Which two parameters should you configure in /etc/security/pwquality.conf or the appropriate pam_pwquality.so line? (Select TWO)

    Show answer & explanation

    Correct answers: A, E

    The difok parameter specifies the number of characters in the new password that must not be present in the old password.

    To prevent reuse of the last 5 passwords, the remember=5 option must be used with pam_pwhistory.so (usually in system-auth and password-auth). The difok=3 parameter in pwquality.conf handles the character difference requirement.

  5. Question 5Beginner

    Configure system auditing · Enable prepackaged rules

    You have customized the system audit rules in /etc/audit/rules.d/99-custom.rules. You want to load these rules immediately without rebooting the system. Which command should you run to load the rules from the configuration files into the kernel?

    Show answer & explanation

    Correct answer: A

    The augenrules script merges all files from /etc/audit/rules.d/ into /etc/audit/audit.rules. The --load argument then loads these rules into the kernel immediately.

  6. Question 6Advanced

    Enforce security compliance using OpenSCAP · Generate and apply a playbook from customized XML for remediation of inventory hosts

    Case Study:

    Company Background
    TechSafe Solutions is deploying a new secure logging infrastructure. All servers run Red Hat Enterprise Linux 9.

    Requirement
    You need to configure OpenSCAP to scan systems nightly. The security policy requires that all systems adhere to the PCI-DSS profile. If a system fails the scan, it should automatically attempt to remediate using an Ansible Playbook generated from the scan results.

    Current Situation
    You have installed openscap-scanner and scap-security-guide. You have performed a manual scan using oscap and verified the failures.

    Question
    Which command sequence best generates a remediation Ansible playbook based strictly on the failed results of a previous scan stored in results.xml?

    Show answer & explanation

    Correct answer: A

    The oscap xccdf generate fix command is used to generate remediation scripts. Specifying --fix-type ansible generates an Ansible playbook. Using the input file results.xml (which contains TestResults) ensures the playbook only targets the rules that failed in that specific scan, rather than all rules in the profile.

Ready for the real thing?

The full EX415 simulator has every exam-style question, timed mode, and instant scoring.

Go to the EX415 simulator →