Courseiva
Security →hardMultiple Choice

XK0-006 Security Practice Question

A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?

⚠ Common exam trap

It's easy for candidates to confuse the --permanent flag with the need to reload, or assuming that adding a service or separate source/port achieves the same granular restriction as a rich rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload

Using a rich rule with --permanent allows granular control, specifying source address, port, and protocol in one rule. The subsequent reload applies the permanent configuration to the runtime environment. This meets the requirement of restricting access to the internal subnet on port 443 and ensuring persistence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --runtime-to-permanent

    Why it's wrong here

    This adds a runtime rich rule and then converts the runtime configuration to permanent, which would also make it persistent. However, it does not explicitly use --permanent when adding the rule, and the runtime-to-permanent command would save all current runtime rules, potentially including unintended ones. The sequence is less precise for this specific requirement.

  • ✗

    firewall-cmd --permanent --zone=public --add-service=https && firewall-cmd --reload

    Why it's wrong here

    This adds the predefined https service to the public zone permanently, which opens port 443 to all sources, not just the internal subnet. The requirement is to restrict access to 192.168.1.0/24, so using the https service would be too permissive and fail the security objective.

  • ✗

    firewall-cmd --permanent --zone=public --add-source=192.168.1.0/24 --add-port=443/tcp && firewall-cmd --reload

    Why it's wrong here

    This adds the source subnet and port to the public zone, but it does not create a specific rule that ties the source to the port. In firewalld, adding a source and a port separately allows any traffic from that source to any port, and any source to port 443, which is not the intended restriction.

  • ✓

    firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload

    Why this is correct

    This command adds a permanent rich rule to the public zone that accepts IPv4 traffic from the specified subnet to TCP port 443, then reloads firewalld to apply the change immediately. The --permanent flag ensures the rule survives reboots, and the reload activates it without dropping existing connections.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.