Ya, so there must have been a change at some point. Setting the zone to drop and then adding services allows those services through. Firewalld site shows what your book says is correct and what (I'm 99% sure) I saw when I initially started with the SCAP stuff last year:
0_1505511440757_drop-site.png
However, here are the actual results:
0_1505511232007_drop.png
0_1505511240422_nmap.png