CompTIA Linux+ (XK0-006)SecurityHard

A security engineer is migrating firewall rules from iptables to nftables on a new server and needs to add a rule dropping all incoming TCP traffic on port 23 (Telnet) within the existing inet filter table's input chain. Which command is correct?

  1. Anft add rule inet filter input tcp dport 23 drop
  2. Biptables -A INPUT -p tcp --dport 23 -j DROP
  3. Cnft insert chain inet filter input tcp dport 23 drop
  4. Dnft add table inet filter tcp dport 23 drop
Show answer & explanation

Correct answer: A. nft add rule inet filter input tcp dport 23 drop

The nftables syntax for adding a rule to an existing chain is 'nft add rule <family> <table> <chain> <matches> <action>'. Here that becomes nft add rule inet filter input tcp dport 23 drop, which appends a rule to the input chain of the inet filter table matching TCP port 23 and dropping it.

Why the other options are wrong

  • B. This is valid iptables syntax, but the scenario specifically requires migrating to nftables syntax.
  • C. nft has no 'insert chain' subcommand with match criteria; chains are created with 'add chain', and rules use 'add rule' or 'insert rule'.
  • D. add table only creates or references a table; it cannot take match/action parameters like tcp dport or drop.

nftables Rule Syntax

nftables organizes rules into tables (address families) containing chains (hook points) containing rules; the base command to add a rule is 'nft add rule <family> <table> <chain> <expression>'.

  • Families: ip, ip6, inet, arp, bridge, netdev
  • Tables are created with 'nft add table'
  • Chains need base chain type/hook/priority when created with 'nft add chain'
  • Rules are added with 'nft add rule' or inserted at top with 'nft insert rule'

Memory trick: Table holds Chain holds Rule — like a filing cabinet, drawer, and folder.

More Security questions