Firewall and Network Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall and Network Security flashcards as text
Which tool is the recommended modern replacement for iptables on systems using nftables as the backend?
Answer: iptables-nft
iptables-nft is a compatibility layer that translates iptables syntax to nftables rules, bridging the two frameworks.
What does the 'INVALID' connection state mean in iptables stateful filtering?
Answer: The packet doesn't match any known connection or is malformed
INVALID means the packet cannot be associated with any tracked connection and may indicate a scan or attack.
In firewalld, which command lists all available predefined services that can be added to a zone?
Answer: firewall-cmd --get-services
'--get-services' lists all predefined service names available in firewalld's service directory.
Which iptables module allows you to match packets based on the time of day or day of the week?
Answer: -m time
The 'time' match module lets you apply rules based on time ranges, dates, and days of the week.
What does 'ip6tables' manage compared to 'iptables'?
Answer: IPv6 packet filtering rules
ip6tables is the IPv6-specific counterpart to iptables and manages netfilter rules for IPv6 traffic.
Which command makes iptables rules persistent across reboots on Debian/Ubuntu systems?
Answer: iptables-save > /etc/iptables/rules.v4
On Debian/Ubuntu, iptables-save redirects rules to /etc/iptables/rules.v4, which iptables-restore loads at boot via the iptables-persistent package.
What is the effect of setting the default policy of the FORWARD chain to DROP?
Answer: Stops all traffic from being routed between network interfaces
The FORWARD chain handles routed traffic passing through the Linux host; a DROP default blocks all such inter-interface routing.