Firewall and Network Security Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Firewall and Network Security flashcards as text
Which nftables hook corresponds to locally generated outbound traffic on a Linux host?
Answer: output
The 'output' hook in nftables processes packets generated by local processes before they leave the network interface.
What firewall technique does 'iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE' implement?
Answer: IP masquerading (source NAT)
MASQUERADE is a form of SNAT that dynamically replaces the source IP with the outbound interface's IP, used for internet sharing.
Which iptables module limits the rate of log messages to prevent log flooding?
Answer: -m limit
The 'limit' module restricts how frequently a rule matches, commonly paired with LOG to prevent syslog from being overwhelmed.
In SELinux, what does the 'enforcing' mode do to policy violations?
Answer: Blocks and logs violations
Enforcing mode actively blocks actions that violate SELinux policy and records denials in the audit log.
Which command adds a rich rule in firewalld to block all traffic from the IP 192.168.1.100?
Answer: firewall-cmd --add-rich-rule='rule family=ipv4 source address=192.168.1.100 drop'
firewalld rich rules use the '--add-rich-rule' flag with a structured rule string to allow complex matching conditions.
What is the primary purpose of the 'raw' table in iptables?
Answer: Allows rules to exempt packets from connection tracking
The raw table is processed before conntrack and is used with NOTRACK to exempt specific traffic from connection state tracking.
Which /proc entry shows the current number of tracked connections in the netfilter connection table?
Answer: /proc/sys/net/netfilter/nf_conntrack_count
/proc/sys/net/netfilter/nf_conntrack_count displays the current number of active entries in the connection tracking table.