XK0-006 Security Practice Question
A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?
⚠ Common exam trap
It's easy for candidates to confuse the --permanent flag with the need to reload, or assuming that adding a service or separate source/port achieves the same granular restriction as a rich rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload
Using a rich rule with --permanent allows granular control, specifying source address, port, and protocol in one rule. The subsequent reload applies the permanent configuration to the runtime environment. This meets the requirement of restricting access to the internal subnet on port 443 and ensuring persistence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --runtime-to-permanent
Why it's wrong here
This adds a runtime rich rule and then converts the runtime configuration to permanent, which would also make it persistent. However, it does not explicitly use --permanent when adding the rule, and the runtime-to-permanent command would save all current runtime rules, potentially including unintended ones. The sequence is less precise for this specific requirement.
- ✗
firewall-cmd --permanent --zone=public --add-service=https && firewall-cmd --reload
Why it's wrong here
This adds the predefined https service to the public zone permanently, which opens port 443 to all sources, not just the internal subnet. The requirement is to restrict access to 192.168.1.0/24, so using the https service would be too permissive and fail the security objective.
- ✗
firewall-cmd --permanent --zone=public --add-source=192.168.1.0/24 --add-port=443/tcp && firewall-cmd --reload
Why it's wrong here
This adds the source subnet and port to the public zone, but it does not create a specific rule that ties the source to the port. In firewalld, adding a source and a port separately allows any traffic from that source to any port, and any source to port 443, which is not the intended restriction.
- ✓
firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload
Why this is correct
This command adds a permanent rich rule to the public zone that accepts IPv4 traffic from the specified subnet to TCP port 443, then reloads firewalld to apply the change immediately. The --permanent flag ensures the rule survives reboots, and the reload activates it without dropping existing connections.
Visual reference
Go deeper
Related to this question
Learn chapter
Firewall and Security Basics
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.