100+ Free EX415 Practice Questions
Pass your Red Hat Certified Specialist in Security: Linux (EX415) exam on the first try — instant access, no signup required.
Which command shows the current SELinux mode (Enforcing, Permissive, or Disabled) on a RHEL 9 system?
Key Facts: EX415 Exam
210/300
Passing Score
Red Hat
4 hours
Exam Length
Red Hat
Hands-on
Format
Performance-based
RHEL 9
Tested Version
Red Hat
RHCA-eligible
Counts toward
Red Hat Certified Architect
$400-500
Exam Cost
Red Hat
EX415 is a 4-hour performance-based hands-on exam (no multiple choice) on live RHEL 9 systems. The passing score is 210/300 (70%). Candidates must configure SELinux policy, run OpenSCAP scans and apply remediation profiles, build audit rules, deploy NBDE with Tang/Clevis, lock down USB devices with USBGuard, harden kernel parameters, and forward logs centrally with rsyslog. EX415 counts toward Red Hat Certified Architect (RHCA).
Sample EX415 Practice Questions
Try these sample questions to test your EX415 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which command shows the current SELinux mode (Enforcing, Permissive, or Disabled) on a RHEL 9 system?
2An administrator wants Apache to make outbound network connections to a remote database. Which SELinux boolean must be set persistently?
3After serving content from a non-default directory /web, Apache returns 403 errors. The administrator confirms the file permissions are correct. What is the most likely SELinux fix?
4Which SELinux command lists all booleans along with their current state and a short description?
5An nginx process must listen on TCP port 8443 in addition to 443. Which command persistently allows that under SELinux?
6After collecting AVC denials in /var/log/audit/audit.log, which command generates a custom policy module that allows the denied actions?
7Which command installs a compiled SELinux policy module produced by audit2allow?
8An admin wants only the httpd_t domain to run in permissive mode for debugging while keeping the rest of the system enforcing. Which command does this?
9Which file controls the default SELinux mode applied at boot?
10After moving /home to a new filesystem, users cannot log in via SSH and SELinux denials reference home_root_t. What is the cleanest fix?
About the EX415 Exam
EX415 is the Red Hat Certified Specialist in Security: Linux exam. It validates hands-on skills hardening RHEL 9 with SELinux (booleans, fcontext, custom policy modules), OpenSCAP compliance scanning and remediation against PCI-DSS/CIS/ANSSI/STIG profiles, the audit framework (auditd/auditctl/ausearch), USBGuard, system-wide cryptographic policies, AIDE file integrity, kernel hardening via sysctl, PAM-based authentication controls, network-bound disk encryption (Tang/Clevis with LUKS2), and centralized log collection with rsyslog.
Questions
100 scored questions
Time Limit
4 hours
Passing Score
210/300 (70%)
Exam Fee
$400-500 USD (Red Hat)
EX415 Exam Content Outline
Configure SELinux
Booleans (setsebool -P), file contexts (semanage fcontext, restorecon), audit2allow, custom policy modules, targeted policy
Compliance scanning with OpenSCAP
oscap xccdf eval, profiles (PCI-DSS, CIS, ANSSI, STIG), --remediate, Bash and Ansible remediation
Configure system auditing
auditd, auditctl, ausearch -k, aureport, audispd plugins, immutable audit rules, audit log retention
Network-Bound Disk Encryption (NBDE)
LUKS2, Tang server, Clevis pins (tang, tpm2, sss), automatic boot unlock, key rotation
USBGuard
usbguard generate-policy, list-devices, allow-device, IPC ACLs, device authorization at boot
System-wide crypto policies
update-crypto-policies (DEFAULT, FUTURE, LEGACY, FIPS), subpolicies, /etc/crypto-policies
AIDE file integrity
aide --init, aide --check, /etc/aide.conf rules, baseline updates, scheduled scans
Kernel hardening (sysctl) and PAM/AAA
sysctl keys (kernel.kptr_restrict, fs.suid_dumpable), pam_faillock, pam_pwquality, /etc/security/limits
Centralized log collection (rsyslog)
rsyslog forwarding (@@host:port), TLS for log transport (RELP), omfwd, retention policies
Auditing changes and reporting
ausearch -k, aureport --summary, audit-viewer, integration with SIEM/log forwarding
How to Pass the EX415 Exam
What You Need to Know
- Passing score: 210/300 (70%)
- Exam length: 100 questions
- Time limit: 4 hours
- Exam fee: $400-500 USD
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
EX415 Study Tips from Top Performers
Frequently Asked Questions
What does EX415 cover?
EX415 is the Red Hat Certified Specialist in Security: Linux exam. It tests hardening RHEL 9 with SELinux (booleans, fcontext, custom modules), OpenSCAP compliance scanning and remediation against PCI-DSS/CIS/ANSSI/STIG, the audit framework (auditd/auditctl/ausearch), USBGuard, system-wide crypto policies, AIDE, kernel hardening via sysctl, PAM controls, NBDE (Tang/Clevis with LUKS2), and centralized rsyslog forwarding.
What is the EX415 exam format?
EX415 is performance-based: there are no multiple-choice questions. You receive a list of security tasks to complete on live RHEL 9 systems within roughly 4 hours. Passing requires 210 out of 300 points (70%). Each task is graded based on whether the resulting system state meets the specification — partial credit is possible only when objectives are scored independently.
How long is the EX415 exam?
EX415 is approximately a 4-hour single-session performance-based exam. Red Hat administers it at training centers, partner sites, and via individual remote exam (proctored). Time management is critical because OpenSCAP scans, AIDE baselines, and SELinux relabel operations can each consume several minutes during the test.
What is the EX415 cost?
Red Hat lists the standard exam fee around $400-500 USD depending on region, with discounts often included in the Red Hat Learning Subscription. Individual exam vouchers are also available. Always confirm the current fee on the official EX415 page before scheduling.
Does EX415 require RHCE?
Red Hat strongly recommends current RHCE certification before attempting EX415, since the exam includes Ansible-based remediation through OpenSCAP and ansible-hardening. RHCE is also required to retain Specialist credentials and is part of the path to Red Hat Certified Architect (RHCA).
How long should I study for EX415?
Plan for 80-120 hours of focused, hands-on study over 8-12 weeks. Set up a lab with at least one RHEL 9 server (target), one client, and one Tang server. Practice every objective in the official content guide repeatedly until you can complete each task in a few minutes from memory.
Is EX415 valid for life?
No. Specialist credentials follow Red Hat's general 3-year recertification cycle and require a current RHCE to remain valid. You can re-pass EX415 or earn a higher Red Hat credential to keep it active.