CompTIA Linux+ (XK0-006)SecurityHard
A security engineer is migrating firewall rules from iptables to nftables on a new server and needs to add a rule dropping all incoming TCP traffic on port 23 (Telnet) within the existing inet filter table's input chain. Which command is correct?
- Anft add rule inet filter input tcp dport 23 drop
- Biptables -A INPUT -p tcp --dport 23 -j DROP
- Cnft insert chain inet filter input tcp dport 23 drop
- Dnft add table inet filter tcp dport 23 drop
Show answer & explanationAnswer & explanation
Correct answer: A. nft add rule inet filter input tcp dport 23 drop
The nftables syntax for adding a rule to an existing chain is 'nft add rule <family> <table> <chain> <matches> <action>'. Here that becomes nft add rule inet filter input tcp dport 23 drop, which appends a rule to the input chain of the inet filter table matching TCP port 23 and dropping it.
Why the other options are wrong
- B. This is valid iptables syntax, but the scenario specifically requires migrating to nftables syntax.
- C. nft has no 'insert chain' subcommand with match criteria; chains are created with 'add chain', and rules use 'add rule' or 'insert rule'.
- D. add table only creates or references a table; it cannot take match/action parameters like tcp dport or drop.
nftables Rule Syntax
nftables organizes rules into tables (address families) containing chains (hook points) containing rules; the base command to add a rule is 'nft add rule <family> <table> <chain> <expression>'.
- Families: ip, ip6, inet, arp, bridge, netdev
- Tables are created with 'nft add table'
- Chains need base chain type/hook/priority when created with 'nft add chain'
- Rules are added with 'nft add rule' or inserted at top with 'nft insert rule'
Memory trick: Table holds Chain holds Rule — like a filing cabinet, drawer, and folder.