Firewall and Network Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall and Network Security flashcards as text
Which iptables table is responsible for altering packet headers such as TTL and TOS fields?
Answer: mangle
The mangle table is used to modify packet headers, including TTL, TOS, and MARK fields.
What nftables command lists all current rules across all tables and chains?
Answer: nft list ruleset
'nft list ruleset' outputs the complete nftables configuration including all tables, chains, and rules.
Which firewalld zone is most restrictive and drops all incoming connections without any notification?
Answer: drop
The 'drop' zone silently discards all incoming packets, while 'block' sends an ICMP rejection message.
In iptables, what does the '-j RETURN' target do when used inside a user-defined chain?
Answer: Returns to the calling chain and continues matching
RETURN exits the current user-defined chain and resumes rule matching in the parent chain that invoked it.
Which command adds a permanent firewalld service rule to the public zone without applying it immediately?
Answer: firewall-cmd --zone=public --add-service=http --permanent
The --permanent flag writes the rule to the persistent configuration but requires --reload to take effect at runtime.
What is the purpose of the 'conntrack' module in Linux netfilter?
Answer: Tracks connection state for stateful filtering
conntrack (connection tracking) maintains a state table allowing the firewall to distinguish NEW, ESTABLISHED, and RELATED connections.
Which iptables command displays the packet and byte counters for all rules in the INPUT chain?
Answer: iptables -L INPUT -v
The -v (verbose) flag adds packet and byte counters to the iptables listing output.