EX200 Deploy, configure, and maintain systems Practice Question
An administrator wants to temporarily disable the firewalld service for troubleshooting. Which command will stop the service and prevent it from starting on subsequent boots?
⚠ Common exam trap
Candidates often confuse `disable` with `mask` or forget that `stop` alone does not affect boot-time behavior, leading them to choose options that either stop the service without disabling it or permanently block it with mask.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
systemctl disable --now firewalld
`systemctl disable --now firewalld` both stops the service immediately (via `--now`) and disables it from starting automatically on subsequent boots. This meets the requirement of temporarily disabling the service for troubleshooting while preventing it from starting after reboot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
systemctl stop --now firewalld
Why it's wrong here
The --now flag is a systemd modifier that is only valid with action verbs like enable, disable, or mask; it cannot be combined with stop. Since systemctl stop already halts the service immediately, giving --now is syntactically invalid and systemd will abort the command with an 'unrecognized option' error. As a result, firewalld remains active and keeps running.
- ✗
systemctl mask firewalld
Why it's wrong here
Masking firewalld creates a symlink from the unit file to /dev/null, preventing any process—including root—from starting it even manually, which is far more aggressive than a temporary shutdown. The command does not stop the currently active firewalld process, and to reverse the change you must run systemctl unmask firewalld. For a short troubleshooting window, this is overkill and can mask regressions in service configuration.
- ✗
systemctl stop firewalld
Why it's wrong here
This halts the running firewalld daemon and flushes its active rules, but it only affects the live state; the service's enablement symlinks in /etc/systemd/system remain intact. Because the unit is still enabled, systemd will automatically restart firewalld on the next boot. To make the firewall stay down until you deliberately restart it, you also need to run systemctl disable firewalld or use the combined --now form.
- ✗
systemctl disable firewalld
Why it's wrong here
This removes the boot-time enablement symlinks for firewalld, so the service will not be pulled in during future system startup, but it leaves the currently running firewalld process untouched. The firewall continues to enforce whatever rules are loaded right now, and a reboot would also be required to make it go away. For immediate effect, you must stop the service in addition, which is why disable alone is only half the job.
- ✓
systemctl disable --now firewalld
Why this is correct
Running systemctl disable --now firewalld performs both operations atomically: it stops the active firewalld daemon and removes the boot-time enablement symlinks so that the service will not start at the next boot. This is the cleanest way to temporarily take the firewall down across reboots while leaving the unit unmasked and available for manual start later. It is the standard single-command answer for 'temporarily disable' scenarios.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.