Linux · SELinux & AppArmor
A daemon already runs under its own restricted account with the right rwx permissions, yet you also want the kernel to stop it touching directories it has no business in even if it is hijacked. What extra layer provides this?
Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.
