CompTIA Linux+ (XK0-006)SecurityEasy
A technician created a new firewalld zone named 'internal' with restricted services. After running 'firewall-cmd --zone=internal --add-interface=eth0', the assignment worked immediately, but disappeared after the server rebooted. Which command permanently assigns eth0 to the internal zone?
- Afirewall-cmd --set-default-zone=internal --interface=eth0
- Bfirewall-cmd --zone=internal --add-interface=eth0
- Cfirewall-cmd --zone=internal --add-source=eth0 --permanent
- Dfirewall-cmd --permanent --zone=internal --change-interface=eth0
Show answer & explanationAnswer & explanation
Correct answer: D. firewall-cmd --permanent --zone=internal --change-interface=eth0
The --permanent flag combined with --change-interface writes the interface-to-zone mapping to firewalld's persistent configuration (NetworkManager connection or firewalld zone XML), surviving reboots. Runtime-only commands like the original one are lost at reboot.
Why the other options are wrong
- A. --set-default-zone changes the default zone globally and doesn't take an --interface argument this way.
- B. This is the exact runtime-only command the technician already ran, which does not persist.
- C. --add-source assigns an IP/subnet source, not a network interface, to a zone.
firewalld Interface-to-Zone Binding
firewalld maps network interfaces to zones; runtime changes are temporary unless made with --permanent or written to NetworkManager connection profiles.
- firewall-cmd --get-active-zones shows current bindings
- --permanent requires --reload to take runtime effect
- --change-interface replaces any existing zone assignment for that interface
- Default zone applies to unassigned interfaces
Memory trick: No --permanent, no persistence — it vanishes like a runtime ghost.