EX200 Manage security Practice Question
Which three statements about firewalld zones are correct? (Choose three.)
⚠ Common exam trap
A common mix-up: candidates assume a network interface can belong to multiple zones simultaneously (like in some other firewall systems), but firewalld enforces a strict one-interface-per-zone binding, and they may also forget that zones support 'REJECT' and 'default' targets, not just 'DROP' and 'ACCEPT'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The default zone can be changed using firewall-cmd.
The default zone in firewalld can be changed using the 'firewall-cmd --set-default-zone=<zone>' command. This command updates the runtime and permanent configuration, ensuring that all new network interfaces are automatically assigned to the specified zone unless explicitly overridden.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The default zone can be changed using firewall-cmd.
Why this is correct
The default zone can be changed with `firewall-cmd --set-default-zone=<zone>`. This command updates the default zone in the firewalld configuration, so the change persists across reboots. The default zone applies only to interfaces or source addresses that have not been explicitly bound to another zone.
- ✗
A network interface can be assigned to multiple zones simultaneously.
Why it's wrong here
An interface is bound to exactly one zone at a time, because the zone defines a single policy for all traffic entering through that interface. If an interface were in two zones, firewalld would have to resolve conflicting accept/drop rules, which is not supported. To move an interface, use `firewall-cmd --change-interface=eth0 --zone=internal`, which replaces the previous zone binding.
- ✓
The 'public' zone is more restrictive than the 'trusted' zone.
Why this is correct
In the built-in zone set, the `trusted` zone has an ACCEPT target, meaning all incoming packets are accepted by default. The `public` zone uses the default target and only permits a whitelist of services such as SSH and DHCPv6; all other incoming traffic is rejected or dropped. Thus a host in the `public` zone is deliberately exposed to far less network traffic than one in `trusted`, making it the more restrictive choice.
- ✓
Rich rules can specify source and destination addresses.
Why this is correct
Rich rules extend firewalld beyond simple services and ports by allowing an explicit rule to constrain both the source address and the destination address. For example, `firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.0.2.1 destination address=203.0.113.5 port port=8080 protocol=tcp accept'` only matches traffic from that specific source going to that specific local IP. This capability is useful for narrowly scoped access controls that would otherwise require multiple separate rules or IPset workarounds.
- ✗
Zones can have a default target of only 'DROP' or 'ACCEPT'.
Why it's wrong here
A zone's target can be `default`, `ACCEPT`, `REJECT`, or `DROP`, so limiting the options to DROP and ACCEPT is incorrect. The `default` target relies on the services, ports, and rich rules defined in the zone to determine whether to accept a packet, while `REJECT` actively sends an ICMP error and `DROP` silently discards the packet. Built-in zones like `public` and `home` use `default`, not DROP or ACCEPT.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.