CompTIA Linux+ (XK0-006)SecurityMedium

A pilot deployment requires a web server's HTTP service to be reachable permanently, including after the next reboot, using firewalld on a RHEL-based system. Which command sequence correctly achieves this?

  1. Afirewall-cmd --zone=public --add-port=80/tcp
  2. Bfirewall-cmd --zone=public --add-service=http --permanent; firewall-cmd --reload
  3. Cfirewall-cmd --add-service=http
  4. Diptables -A INPUT -p tcp --dport 80 -j ACCEPT
Show answer & explanation

Correct answer: B. firewall-cmd --zone=public --add-service=http --permanent; firewall-cmd --reload

firewalld changes without --permanent apply only to the current runtime configuration and are lost on reload or reboot. Adding --permanent writes the rule to the permanent configuration, and firewall-cmd --reload applies it immediately while keeping both runtime and permanent configs in sync.

Why the other options are wrong

  • A. Opens a port instead of a named service, and also lacks --permanent so it is not persistent.
  • C. Without --permanent, this rule disappears after a reload or reboot.
  • D. iptables commands do not interact with firewalld's configuration and could conflict with it on modern systems.

firewalld Persistence

firewalld rules must be added with --permanent to survive reloads/reboots; firewall-cmd --reload then applies permanent rules to the active runtime configuration.

  • Runtime rules are temporary, lost on reload/reboot
  • --permanent writes to /etc/firewalld/zones/
  • --reload merges permanent config into runtime
  • firewall-cmd --list-all shows active rules for a zone

Memory trick: No --permanent, no future—rules vanish like sandcastles without the permanent seal.

More Security questions