Courseiva

EX200 Manage users and groups Practice Question

Match each firewall zone to its default trust level.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Low trust; only allow selected incoming connections

Moderate trust; for private networks

High trust; accept all connections

For publicly accessible systems isolated from internal network

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

drop: No traffic is sent, and incoming packets are dropped without reply.

Correct matches: drop blocks all traffic silently, public allows only basic services, internal allows more services, trusted allows all. Common confusions include mixing drop with trusted or public with internal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    drop: No traffic is sent, and incoming packets are dropped without reply.

    Why this is correct

    The drop zone represents the minimum trust baseline in firewalld's default zone model. With this zone active, every inbound packet is discarded without sending an ICMP error or TCP RST, so the sender receives no feedback and connection attempts simply time out. This makes it distinct from the reject target, which actively refuses traffic with a reply, and underscores why no services should be expected to function in this state.

  • ✓

    public: Only basic services (e.g., SSH) are allowed, low trust.

    Why this is correct

    The public zone is intended for use on untrusted networks such as coffee shop Wi-Fi or the internet-facing side of a host. Its default policy denies most inbound traffic while permitting only a small set of predefined services, commonly including SSH, and optionally DHCPv6-client, to allow basic administration and address assignment. The limited allowlist means network services that are not explicitly enabled remain unreachable, giving it a low but non-zero trust level above drop.

  • ✓

    internal: Medium to high trust, typically for corporate internal networks.

    Why this is correct

    The internal zone is designed for networks where the host and other systems are mutually trusted to a moderate degree, such as a corporate LAN or site-to-site VPN environment. It permits a broader set of inbound services by default, including SSH, DHCP, and often Samba or mDNS, reflecting a medium-to-high trust posture where legitimate internal clients are expected to connect freely. However, unlike the trusted zone, it still applies firewall filtering and requires services to be explicitly allowed rather than accepting all traffic unconditionally.

  • ✓

    trusted: All network connections are accepted.

    Why this is correct

    The trusted zone is the most permissive default area in firewalld, with a default target of ACCEPT. Any inbound packet is accepted as long as it matches no deny rule, meaning all network connections—including unsolicited ones—are allowed without service-specific exceptions. This configuration is appropriate only for highly controlled networks, such as a dedicated management LAN or lab segment, where the risk of unauthorized access is minimal.

  • ✗

    drop: All network connections are accepted.

    Why it's wrong here

    This answer confuses the drop zone's target with the trusted zone's ACCEPT target. The drop zone actually has a target of DROP, meaning incoming packets are silently discarded with no response sent, making it the least trusted zone. Accepting all network connections is the defining behavior of the trusted zone, which has the highest trust level, so this pairing is incorrect.

  • ✗

    public: Medium to high trust.

    Why it's wrong here

    Assigning medium-to-high trust to the public zone is incorrect because the public zone is explicitly intended for untrusted, public-facing networks. Its default configuration only allows a few basic services, such as SSH, and drops the majority of unsolicited inbound traffic. Medium-to-high trust characterizes the internal zone, which permits a wider range of services for corporate intranet hosts, not the public zone.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.