CompTIA Linux+ (XK0-006)SecurityEasy

A technician created a new firewalld zone named 'internal' with restricted services. After running 'firewall-cmd --zone=internal --add-interface=eth0', the assignment worked immediately, but disappeared after the server rebooted. Which command permanently assigns eth0 to the internal zone?

  1. Afirewall-cmd --set-default-zone=internal --interface=eth0
  2. Bfirewall-cmd --zone=internal --add-interface=eth0
  3. Cfirewall-cmd --zone=internal --add-source=eth0 --permanent
  4. Dfirewall-cmd --permanent --zone=internal --change-interface=eth0
Show answer & explanation

Correct answer: D. firewall-cmd --permanent --zone=internal --change-interface=eth0

The --permanent flag combined with --change-interface writes the interface-to-zone mapping to firewalld's persistent configuration (NetworkManager connection or firewalld zone XML), surviving reboots. Runtime-only commands like the original one are lost at reboot.

Why the other options are wrong

  • A. --set-default-zone changes the default zone globally and doesn't take an --interface argument this way.
  • B. This is the exact runtime-only command the technician already ran, which does not persist.
  • C. --add-source assigns an IP/subnet source, not a network interface, to a zone.

firewalld Interface-to-Zone Binding

firewalld maps network interfaces to zones; runtime changes are temporary unless made with --permanent or written to NetworkManager connection profiles.

  • firewall-cmd --get-active-zones shows current bindings
  • --permanent requires --reload to take runtime effect
  • --change-interface replaces any existing zone assignment for that interface
  • Default zone applies to unassigned interfaces

Memory trick: No --permanent, no persistence — it vanishes like a runtime ghost.

More Security questions