Courseiva
Manage security →hardMultiple Choice

EX200 Manage security Practice Question

A company requires that SSH access from the external network (10.0.1.0/24) only be allowed to port 2222, and all other incoming traffic on the firewall should be dropped. Which firewalld rule should be applied to the external zone?

⚠ Common exam trap

Candidates often confuse the 'service name' with a custom port, selecting Option C which uses the SSH service (port 22) instead of the required port 2222, or they forget to restrict the source address as in Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" port port="2222" protocol="tcp" accept' --permanent

It uses a rich rule to explicitly allow incoming TCP traffic on port 2222 from the 10.0.1.0/24 source network, which matches the requirement. The default target for the external zone is 'drop', so only explicitly permitted traffic is allowed; this rule ensures SSH on port 2222 is accepted while all other incoming traffic is dropped.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    firewall-cmd --zone=external --add-service=ssh --permanent

    Why it's wrong here

    This command opens the predefined ssh service (TCP port 22) to every source address in the external zone because no source restriction is specified. That would expose the SSH daemon to the entire external network, whereas the requirement is to limit SSH access from the Internet to only the 10.0.1.0/24 subnet and to the non-standard port 2222. Therefore it is both over-permissive and uses the wrong port.

  • ✗

    firewall-cmd --zone=external --add-port=2222/tcp --permanent

    Why it's wrong here

    Adding --add-port=2222/tcp to the external zone without a rich rule or source address allows any IP address on the Internet to reach port 2222/tcp. This satisfies the port requirement but completely ignores the restriction to the 10.0.1.0/24 source subnet, making it too broad. A port-only rule applies to all sources, so it fails the stated access-control requirement.

  • ✗

    firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" service name="ssh" accept' --permanent

    Why it's wrong here

    This rich rule correctly confines SSH access to the 10.0.1.0/24 source subnet, but it references the service name ssh, which firewalld maps to port 22/tcp. Since the company runs SSH on port 2222, this rule would not permit the actual SSH service; it would open the wrong port. The rule must specify the custom port explicitly, as in the correct answer.

  • ✓

    firewall-cmd --zone=external --add-rich-rule='rule family="ipv4" source address="10.0.1.0/24" port port="2222" protocol="tcp" accept' --permanent

    Why this is correct

    This rich rule combines a source address restriction (10.0.1.0/24) with an explicit port and protocol (2222/tcp), so only that internal subnet can reach the SSH service on the non-standard port. Using port instead of service avoids any ambiguity introduced by default service definitions. With --permanent, the rule survives reloads, and it precisely matches the requirement of limiting external SSH access to the specified source network and port.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.