StudyToCert

All certifications / RHCSA / Lessons

Red Hat Certified System Administrator EX200 (RHEL 10) · Domain 10: Manage security

Setting SELinux enforcing and permissive modes (getenforce, setenforce, /etc/selinux/config)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

SELinux (Security-Enhanced Linux) is mandatory access control built into the kernel. On top of normal file permissions, every process and file carries a security label, and a policy says which process types may access which object types. Even if a service is compromised, SELinux can stop it touching files and ports it was never meant to use. RHEL enables it by default and the RHCSA expects it to stay on.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study RHCSA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the RHCSA study plan