EX200 Deploy, configure, and maintain systems Practice Question
A system administrator wants to allow incoming HTTPS traffic on the default zone of firewalld. Which command should be used?
⚠ Common exam trap
Watch out — candidates often confuse `--add-port` with `--add-service` or forget that omitting `--zone` applies the rule to the default zone, leading them to incorrectly specify a zone or use invalid command syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
firewall-cmd --add-service=https --permanent
The `--add-service=https` option adds the predefined HTTPS service (port 443/tcp) to the firewalld configuration. The `--permanent` flag ensures the rule persists across reboots. By default, the command applies to the default zone if no zone is specified, which matches the requirement to allow HTTPS traffic on the default zone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
firewall-cmd --add-port=443/tcp --zone=public --permanent
Why it's wrong here
This command opens TCP port 443 in the public zone, but it hard-codes the zone. If the system's default zone is not 'public' (e.g., the administrator may have changed the default to 'internal' or 'dmz'), the rule will not apply to the interface where HTTPS traffic arrives. Moreover, using a raw port number bypasses the convenience of the predefined 'https' service, making the rule less self-documenting and more fragile if the service definition changes.
- ✗
firewall-cmd --enable-service=https
Why it's wrong here
The firewalld CLI does not support an '--enable-service' option; this command would fail with an unknown option error. This is not a valid firewalld invocation — the correct flag is '--add-service' to add a service to a zone. Even if the flag were named '--enable', you would still need to specify the zone or rely on the default zone, and you would likely want '--permanent' to make the rule survive a reload.
- ✗
firewall-cmd --add-rule=allow https
Why it's wrong here
There is no '--add-rule' option in firewalld; the closest is '--add-rich-rule', which uses a structured syntax like 'rule service name=https accept' rather than the informal 'allow https'. This command would be rejected as an unknown option, and the words 'allow https' are not a valid firewalld rule specification. To allow HTTPS, you should add the predefined 'https' service with '--add-service', which automatically handles the port and protocol.
- ✓
firewall-cmd --add-service=https --permanent
Why this is correct
This command adds the predefined HTTPS service to the default zone and marks the change as permanent, so it will persist across firewalld reloads and system reboots. The 'https' service definition maps to 'tcp/443', so this is the canonical way to allow incoming web traffic. One subtlety: the permanent configuration does not take effect until a reload (e.g., 'firewall-cmd --reload'), but the command itself is correct and is the expected answer for persisting the rule.
Go deeper
Related to this question
About these practice questions
One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.