Courseiva

EX200 Deploy, configure, and maintain systems Practice Question

Network Topology
# firewall-cmdlist-allpublic (active)target: defaulticmp-block-inversion: nointerfaces: eth0sources:services: dhcpv6-client sshports: 80/tcp 443/tcpprotocols:masquerade: noforward-ports:source-ports:icmp-blocks:rich rules:

Refer to the exhibit. A web server must also accept HTTPS traffic on port 8443. Which command should the administrator run to permanently open this port?

⚠ Common exam trap

The trap here is that candidates often forget the `--permanent` flag or the `--reload` step, assuming that adding a port with `--add-port` alone is sufficient to make it persistent, or they mistakenly use `--add-service` with a port number instead of a service name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

firewall-cmd --add-port=8443/tcp --permanent && firewall-cmd --reload

It uses `--add-port=8443/tcp` to open a non-standard port (8443) for HTTPS traffic, applies the `--permanent` flag to persist the rule across reboots, and then runs `--reload` to activate the change immediately without restarting the firewall service. Without `--reload`, the permanent rule would not take effect until the next firewall reload or system restart.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    firewall-cmd --add-service=8443/tcp --permanent

    Why it's wrong here

    The --add-service option expects a named firewalld service (such as http or https), not a port/protocol string. Passing '8443/tcp' as a service name is invalid because no service with that name is defined, so the command would fail and the permanent configuration would not be updated. To open a non-standard TCP port such as 8443, the correct syntax is --add-port=8443/tcp.

  • ✗

    firewall-cmd --add-port=8443/tcp

    Why it's wrong here

    This command modifies only the runtime firewalld configuration, so the rule disappears after a reboot or firewalld restart. It also never executes --reload, but more importantly it lacks --permanent, meaning the change is not persisted to the permanent configuration. For a persistent HTTPS listener on 8443, you must include --permanent and then issue --reload to activate the saved rule.

  • ✓

    firewall-cmd --add-port=8443/tcp --permanent && firewall-cmd --reload

    Why this is correct

    This correctly adds TCP port 8443 to the persistent configuration of the default zone and then reloads firewalld to make the permanent rule active without restarting services. The --permanent flag writes the rule to the zone's permanent config (e.g., /etc/firewalld/zones/public.xml), and --reload re-applies that config cleanly. This is the proper way to expose a non-standard HTTPS port.

  • ✗

    firewall-cmd --add-port=8443/tcp --zone=public

    Why it's wrong here

    This command applies the port rule to the public zone's runtime configuration only, because --permanent is missing; the default zone is indeed public, so the zone specification is redundant but harmless. After the next firewalld restart or system reboot the rule will be gone. To survive reboots, add --permanent and then run --reload.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.