Firewall and Network Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall and Network Security flashcards as text
Which iptables target sends a TCP RST packet back to the sender instead of silently dropping?
Answer: REJECT --reject-with tcp-reset
REJECT with '--reject-with tcp-reset' sends a TCP RST, causing the sender to see a closed port rather than a timeout.
What does the 'hashlimit' iptables module do differently compared to the 'limit' module?
Answer: It applies rate limits per source IP, destination, or port combination
hashlimit allows per-source-IP (or per-connection) rate limiting, unlike 'limit' which applies a single global rate.
In nftables, what keyword is used to create a stateful firewall rule accepting established and related traffic?
Answer: ct state { established, related } accept
nftables uses 'ct state' (connection tracking state) with set notation to match multiple states in one expression.
Which file defines the default firewalld zone for network interfaces not explicitly assigned to a zone?
Answer: /etc/firewalld/firewalld.conf
The DefaultZone setting in /etc/firewalld/firewalld.conf determines which zone is applied to interfaces without an explicit zone assignment.
What iptables rule would block all outbound SMTP traffic from a Linux server on port 25?
Answer: iptables -A OUTPUT -p tcp --dport 25 -j DROP
To block locally-initiated outbound connections on port 25, add a DROP rule to the OUTPUT chain matching destination port 25.
What is 'port knocking' in the context of Linux firewall security?
Answer: A technique where a specific sequence of connection attempts opens a firewall port
Port knocking keeps ports closed until a predefined sequence of connection attempts is detected, then dynamically opens access.
Which command checks whether a specific firewalld service is currently active (runtime) in the public zone?
Answer: firewall-cmd --zone=public --query-service=http
'--query-service' returns 'yes' or 'no' indicating whether the service is currently enabled in the specified zone at runtime.