EX200 Manage security Practice Question
A system administrator needs to configure a firewall using firewalld to allow incoming HTTPS traffic and deny incoming SSH traffic from a specific source IP 192.168.1.100. Which two commands should be run? (Choose two.)
⚠ Common exam trap
Many candidates confuse `reject` with `drop` in rich rules, or they mistakenly add the HTTP service instead of HTTPS, failing to distinguish between the two services and their respective ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
firewall-cmd --add-service=https --permanent
`firewall-cmd --add-service=https --permanent` adds the HTTPS service (TCP port 443) to the permanent firewall configuration, which is required to allow incoming HTTPS traffic persistently across reboots. The `--permanent` flag ensures the rule survives a reload or restart, and the `--add-service` option uses predefined service definitions from firewalld to simplify rule creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
firewall-cmd --runtime-to-permanent
Why it's wrong here
The firewall-cmd --runtime-to-permanent command persists the current runtime configuration to the permanent configuration files, but it does not itself add any services or rules. If the required HTTPS allow or SSH drop rules were never added to the runtime configuration, this command simply saves an incomplete firewall state. Therefore, it fails to fulfill the requirement to add the necessary firewall rules; it only copies whatever rules are already active.
- ✗
firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.168.1.100 service name=ssh reject' --permanent
Why it's wrong here
Using the reject action in a rich rule causes firewalld to send an ICMP unreachable packet or TCP RST back to 192.168.1.100, explicitly indicating the port is closed. This differs from the desired silent drop, which discards packets without any response, making the host appear nonexistent. A reject action is also more detectable during port scans and does not meet a requirement to hide or block access without feedback.
- ✓
firewall-cmd --add-service=https --permanent
Why this is correct
This command correctly adds the predefined https service to the permanent zone configuration, allowing inbound TCP traffic on port 443. Using --permanent ensures the rule survives reboots, and the https service entry in firewalld maps cleanly to the standard HTTPS port. Since the requirement is to permit secure web traffic, adding the https service is the appropriate, concise way to achieve that with firewalld.
- ✗
firewall-cmd --add-service=http --permanent
Why it's wrong here
This command adds the http service, which opens TCP port 80 for unencrypted web traffic, not port 443 for HTTPS. If the web server must accept secure connections, this rule leaves HTTPS blocked and would cause the initial secure connection attempt to fail. Because the requirement specifically calls for HTTPS, adding http is the wrong service even though the syntax and persistence behavior are valid.
- ✓
firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.168.1.100 service name=ssh drop' --permanent
Why this is correct
This rich rule correctly drops all IPv4 packets from source 192.168.1.100 addressed to the SSH service, using the drop action to silently discard traffic without sending an ICMP error. Because firewalld evaluates rich rules as an ordered set, this gives a specific, per-source override that is more targeted than a blanket SSH rule. The --permanent flag writes the rule to the persistent configuration, making it the correct way to deny SSH from that particular address.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.