Courseiva
Networking →hardMultiple Choice

LFCS Networking Practice Question

A server uses firewalld. Which command permanently allows HTTP traffic?

⚠ Common exam trap

Many exam-takers assume `firewall-cmd --add-service=http` alone is sufficient, forgetting that without `--permanent`, the rule is ephemeral and will be lost on reload or reboot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

firewall-cmd --add-service=http --permanent

The `--permanent` flag is required to make the rule persist across reboots when using `firewall-cmd`. Without it, the rule is only added to the runtime configuration and will be lost after a firewall reload or system restart. The `--add-service=http` parameter uses the predefined service definition for HTTP (port 80/tcp), which is the proper way to allow HTTP traffic in firewalld.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    firewall-cmd --add-service=http

    Why it's wrong here

    Omitting --permanent means the http service is added only to the runtime configuration and disappears on reload or restart. It is tempting because it does allow HTTP immediately, and it would be correct for a temporary runtime-only allowance that need not survive a reboot.

  • ✓

    firewall-cmd --add-service=http --permanent

    Why this is correct

    The `--permanent` flag writes the HTTP service allowance into firewalld's persistent configuration, satisfying the stem's requirement that the change survive a reload or reboot. Without it, the rule would exist only in the runtime configuration and be lost. Running `firewall-cmd --reload` afterwards activates the saved rule.

  • ✗

    firewall-cmd --add-port=80/tcp

    Why it's wrong here

    Without the --permanent flag, firewall-cmd adds the port only to the runtime configuration, so it is lost on reload or reboot. It is tempting because it does open port 80/tcp immediately, and it would be correct when a temporary runtime-only change is genuinely intended.

  • ✗

    systemctl reload firewalld

    Why it's wrong here

    systemctl reload firewalld re-reads the existing permanent configuration into runtime; it adds no port or service itself. It is tempting because it applies permanent rules, and it would be correct after a separate --permanent firewall-cmd change that needs activating without dropping connections.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.