CompTIA Linux+ (XK0-006)SecurityMedium
A pilot deployment requires a web server's HTTP service to be reachable permanently, including after the next reboot, using firewalld on a RHEL-based system. Which command sequence correctly achieves this?
- Afirewall-cmd --zone=public --add-port=80/tcp
- Bfirewall-cmd --zone=public --add-service=http --permanent; firewall-cmd --reload
- Cfirewall-cmd --add-service=http
- Diptables -A INPUT -p tcp --dport 80 -j ACCEPT
Show answer & explanationAnswer & explanation
Correct answer: B. firewall-cmd --zone=public --add-service=http --permanent; firewall-cmd --reload
firewalld changes without --permanent apply only to the current runtime configuration and are lost on reload or reboot. Adding --permanent writes the rule to the permanent configuration, and firewall-cmd --reload applies it immediately while keeping both runtime and permanent configs in sync.
Why the other options are wrong
- A. Opens a port instead of a named service, and also lacks --permanent so it is not persistent.
- C. Without --permanent, this rule disappears after a reload or reboot.
- D. iptables commands do not interact with firewalld's configuration and could conflict with it on modern systems.
firewalld Persistence
firewalld rules must be added with --permanent to survive reloads/reboots; firewall-cmd --reload then applies permanent rules to the active runtime configuration.
- Runtime rules are temporary, lost on reload/reboot
- --permanent writes to /etc/firewalld/zones/
- --reload merges permanent config into runtime
- firewall-cmd --list-all shows active rules for a zone
Memory trick: No --permanent, no future—rules vanish like sandcastles without the permanent seal.