← All Linux Flashcard Decks

Firewall and Network Security Flashcards

36 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Firewall and Network Security flashcards as text
  1. Which command is used to list all current iptables rules in a Linux system?

    Answer: iptables -L

    The `iptables -L` command lists all current firewall rules in all chains. Adding -v gives verbose output and -n prevents DNS lookups.

  2. In iptables, which chain handles packets destined for the local system?

    Answer: INPUT

    The INPUT chain processes packets that are destined for the local machine itself, not forwarded to another host.

  3. What does the `-j DROP` option do in an iptables rule?

    Answer: Silently discards matching packets

    DROP silently discards packets without notifying the sender, unlike REJECT which sends an error message back.

  4. Which firewall tool is the default frontend for managing netfilter on modern systemd-based Linux distributions?

    Answer: firewalld

    firewalld is the default dynamic firewall daemon used on RHEL/CentOS/Fedora systems, providing a zone-based interface to netfilter.

  5. What command allows you to add a permanent rule in firewalld to open port 443/tcp in the public zone?

    Answer: firewall-cmd --zone=public --add-port=443/tcp --permanent

    The correct syntax uses --add-port=443/tcp with --permanent to persist the rule across reboots, followed by --reload to apply it.

  6. Which nftables command lists all current rules and tables?

    Answer: nft list ruleset

    nft list ruleset displays the complete ruleset including all tables, chains, and rules in a human-readable format.

  7. What is the purpose of the UFW (Uncomplicated Firewall) command `ufw enable`?

    Answer: Activates the firewall and enables it to start on boot

    ufw enable both activates the firewall immediately and configures it to start automatically on system boot.

  8. In iptables, what does the `-m state --state ESTABLISHED,RELATED` match condition do?

    Answer: Matches packets that are part of or related to an existing connection

    This stateful matching allows return traffic for already-established connections, essential for a functional firewall that only blocks inbound new connections.

  9. Which command would you use to block all incoming traffic from IP address 203.0.113.5?

    Answer: iptables -A INPUT -s 203.0.113.5 -j DROP

    The -s flag specifies the source IP address, and -j DROP silently discards matching inbound packets.

  10. What does the `ss -tuln` command show?

    Answer: All TCP and UDP listening sockets with numeric addresses

    ss -tuln shows TCP (-t) and UDP (-u) listening (-l) sockets with numeric (-n) addresses and ports, useful for auditing open services.

  11. Which file stores persistent iptables rules on RHEL/CentOS 7+ systems when using the iptables-services package?

    Answer: /etc/sysconfig/iptables

    On RHEL/CentOS systems using iptables-services, rules are saved to /etc/sysconfig/iptables and loaded at boot.

  12. What is the function of the `MASQUERADE` target in iptables?

    Answer: Performs NAT by replacing the source IP with the outgoing interface's IP

    MASQUERADE is used in the POSTROUTING chain for NAT, dynamically replacing source IPs with the interface's current IP — useful when the external IP is dynamic.

  13. Which iptables option inserts a rule at the beginning of a chain rather than appending it to the end?

    Answer: -I

    -I inserts a rule at the specified position (default position 1, the top), while -A appends to the end of the chain.

  14. What does the `fail2ban` service do on a Linux system?

    Answer: Bans IPs that show malicious signs like repeated failed logins

    fail2ban monitors log files for patterns (like failed SSH login attempts) and automatically adds iptables/firewalld rules to ban offending IPs temporarily.

  15. What is the default policy setting approach in a secure Linux firewall configuration?

    Answer: Default DENY on INPUT and FORWARD, default ALLOW on OUTPUT

    A secure firewall denies all inbound and forwarded traffic by default, only allowing explicitly permitted services, while permitting outbound traffic by default.

  16. Which command tests whether a specific port is open on a remote host from the command line?

    Answer: nc -zv host 443

    nc (netcat) with -z (zero I/O mode for scanning) and -v (verbose) tests if a TCP port is open without sending data.

  17. What is the purpose of TCP wrappers (hosts.allow / hosts.deny) in Linux?

    Answer: Control access to services by matching hostnames or IPs against allow/deny lists

    TCP wrappers use /etc/hosts.allow and /etc/hosts.deny to control which hosts can connect to services compiled with libwrap support.

  18. Which nftables table type handles both IPv4 and IPv6 traffic in a single ruleset?

    Answer: inet

    The inet table family handles both IPv4 and IPv6, allowing a single, unified ruleset instead of separate ip and ip6 tables.

  19. What does `iptables -F` do?

    Answer: Flushes (deletes) all rules from all chains in the filter table

    -F (flush) removes all rules from the specified chain or all chains if none specified, but does not change default policies.

  20. Which iptables table is used for Network Address Translation (NAT)?

    Answer: nat

    The nat table handles NAT operations including SNAT, DNAT, and MASQUERADE in the PREROUTING and POSTROUTING chains.