EX200 Manage security Practice Question
A company requires that SSH access from the external network (10.0.1.0/24) only be allowed to port 2222, and all other incoming traffic on the firewall should be dropped. Which firewalld rule should be applied to the external zone?
⚠ Common exam trap
Candidates often confuse the 'service name' with a custom port, selecting Option C which uses the SSH service (port 22) instead of the required port 2222, or they forget to restrict the source address as in Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" port port="2222" protocol="tcp" accept' --permanent
It uses a rich rule to explicitly allow incoming TCP traffic on port 2222 from the 10.0.1.0/24 source network, which matches the requirement. The default target for the external zone is 'drop', so only explicitly permitted traffic is allowed; this rule ensures SSH on port 2222 is accepted while all other incoming traffic is dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
firewall-cmd --zone=external --add-service=ssh --permanent
Why it's wrong here
This command opens the predefined ssh service (TCP port 22) to every source address in the external zone because no source restriction is specified. That would expose the SSH daemon to the entire external network, whereas the requirement is to limit SSH access from the Internet to only the 10.0.1.0/24 subnet and to the non-standard port 2222. Therefore it is both over-permissive and uses the wrong port.
- ✗
firewall-cmd --zone=external --add-port=2222/tcp --permanent
Why it's wrong here
Adding --add-port=2222/tcp to the external zone without a rich rule or source address allows any IP address on the Internet to reach port 2222/tcp. This satisfies the port requirement but completely ignores the restriction to the 10.0.1.0/24 source subnet, making it too broad. A port-only rule applies to all sources, so it fails the stated access-control requirement.
- ✗
firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" service name="ssh" accept' --permanent
Why it's wrong here
This rich rule correctly confines SSH access to the 10.0.1.0/24 source subnet, but it references the service name ssh, which firewalld maps to port 22/tcp. Since the company runs SSH on port 2222, this rule would not permit the actual SSH service; it would open the wrong port. The rule must specify the custom port explicitly, as in the correct answer.
- ✓
firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" port port="2222" protocol="tcp" accept' --permanent
Why this is correct
This rich rule combines a source address restriction (10.0.1.0/24) with an explicit port and protocol (2222/tcp), so only that internal subnet can reach the SSH service on the non-standard port. Using port instead of service avoids any ambiguity introduced by default service definitions. With --permanent, the rule survives reloads, and it precisely matches the requirement of limiting external SSH access to the specified source network and port.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.