SELinux (Security-Enhanced Linux) is mandatory access control built into the kernel. On top of normal file permissions, every process and file carries a security label, and a policy says which process types may access which object types. Even if a service is compromised, SELinux can stop it touching files and ports it was never meant to use. RHEL enables it by default and the RHCSA expects it to stay on.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.