XK0-006 Security Practice Question
A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
firewall-cmd --permanent --add-port=8080/tcp
The correct firewalld command is 'firewall-cmd --permanent --add-port=8080/tcp' followed by '--reload'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
firewall-cmd --zone=public --add-service=8080/tcp --permanent
Why it's wrong here
--add-service expects a named service from firewalld's definitions, such as http or https; 8080/tcp is a port, not a service name, so the command fails. --add-service is correct when opening a predefined service rather than an arbitrary port.
- ✓
firewall-cmd --permanent --add-port=8080/tcp
Why this is correct
The --permanent flag writes the rule into firewalld's persistent configuration rather than only the runtime zone, meeting the requirement that the port stay open across reboots or reloads. The --add-port=8080/tcp argument specifies the exact port and protocol in the default zone.
- ✗
iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
Why it's wrong here
Raw iptables rules bypass firewalld's zone model, so they are not registered in the default zone and are lost when firewalld reloads or restarts. Direct iptables is the right tool only where firewalld is absent or disabled and rules must be hand-managed.
- ✗
firewall-cmd --add-port=8080/tcp
Why it's wrong here
Omitting `--permanent` writes the rule only to the runtime configuration, so the port closes on reload or reboot, failing the persistent requirement. It is tempting because it does open 8080/tcp immediately in the default zone, which suits temporary testing where the change need not survive a restart.
Go deeper
Related to this question
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.