Courseiva
Manage security →mediumMultiple Choice

EX200 Manage security Practice Question

Network Topology
$ sudo firewall-cmdlist-allzone=internalinternal (active)target: defaultinterfaces: eth0services: ssh dhcpv6-clientports:protocols:masquerade: noforward-ports:source-ports:icmp-blocks:rich rules:

Refer to the exhibit. An administrator wants to add the HTTP service (port 80) to the internal zone permanently. Which sequence of commands should be used?

⚠ Common exam trap

It's easy for candidates to confuse --reload with restarting the service, or they think runtime changes persist without the --permanent flag, leading them to choose options that either lose the change (A) or unnecessarily restart firewalld (B).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

firewall-cmd --zone=internal --add-service=http --permanent; firewall-cmd --reload

It uses the --permanent flag to make the rule persistent across reboots, and then runs firewall-cmd --reload to apply the permanent configuration to the running runtime environment without restarting the firewalld service. This sequence ensures the HTTP service is added to the internal zone permanently while maintaining active connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    firewall-cmd --add-service=http --zone=internal; firewall-cmd --reload

    Why it's wrong here

    Adding the service without --permanent creates a runtime-only rule that disappears the moment firewalld reloads or restarts. The subsequent --reload actually erases your change, leaving the internal zone without http access. To persist across reboots and activate the rule cleanly, the permanent configuration must be modified explicitly, not assumed by the runtime command.

  • ✗

    firewall-cmd --permanent --add-service=http --zone=internal; systemctl restart firewalld

    Why it's wrong here

    Using --permanent alone writes the rule to disk, but systemctl restart firewalld is overly disruptive and unnecessary for this scenario. Restarting tears down all firewall rules, active connections, and can interrupt existing traffic, whereas firewalld supports a lightweight reload that applies configuration changes atomically. The Red Hat recommended practice is to use firewall-cmd --reload, which re-reads the permanent config and activates the new service rule without dropping established connections.

  • ✗

    firewall-cmd --zone=internal --add-service=http; firewall-cmd --runtime-to-permanent

    Why it's wrong here

    The runtime command adds http to the active zone, and --runtime-to-permanent saves the entire current runtime state, including any other temporary modifications made earlier. This approach is imprecise and can inadvertently persist unintended runtime-only rules that were never meant to be permanent. The standard and safer method is to use --permanent directly on the add-service command, which targets exactly that rule for persistence and avoids capturing unrelated transient state.

  • ✓

    firewall-cmd --zone=internal --add-service=http --permanent; firewall-cmd --reload

    Why this is correct

    This command correctly combines --permanent to write the http service rule for the internal zone into the active firewalld configuration, then --reload to apply that persisted configuration to the running firewall. Unlike a restart, reload preserves current connections while seamlessly activating the new permanent rule. This two-step sequence is the canonical, exam-accepted method for adding a service and making it effective immediately and after reboot.

About these practice questions

One of 427 original EX200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.