โ† All RHCSA Flashcard Decks

RHCSA Firewalld and Network Configuration Flashcards

7 cards from real RHCSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 RHCSA Firewalld and Network Configuration flashcards as text
  1. Which command sets the default firewalld zone to 'home'?

    Answer: firewall-cmd --set-default-zone=home

    --set-default-zone changes the system-wide default zone immediately without requiring --reload.

  2. On RHEL 9, which tool is the primary recommended method for managing network connections?

    Answer: NetworkManager via nmcli or nmtui

    NetworkManager is the default and recommended network management service on RHEL 9; nmcli and nmtui are its CLI and TUI frontends.

  3. A rich rule must block all traffic from IP 203.0.113.5. Which command achieves this?

    Answer: firewall-cmd --add-rich-rule='rule family=ipv4 source address=203.0.113.5 drop' --permanent

    A rich rule with 'drop' silently discards all packets from the specified source address.

  4. What does the 'ip route show' command display?

    Answer: The kernel routing table

    'ip route show' displays the kernel's IP routing table including default gateway and static routes.

  5. Which nmcli command creates a new Ethernet connection named 'corp' with static IP 10.1.1.10/24 and gateway 10.1.1.1?

    Answer: nmcli con add type ethernet ifname eth1 con-name corp ip4 10.1.1.10/24 gw4 10.1.1.1

    nmcli con add with 'type ethernet', 'ifname', 'con-name', 'ip4', and 'gw4' creates a fully configured static connection.

  6. Which firewalld zone is designed for computers in the same local network that you mostly trust?

    Answer: home

    The 'home' zone is for home networks where you trust most other computers and selected incoming connections are accepted.

  7. What is the effect of running 'firewall-cmd --reload'?

    Answer: Applies the permanent configuration to the runtime without restarting the daemon

    --reload merges permanent rules into the live kernel config without stopping firewalld or dropping existing connections.