CompTIA Linux+ (XK0-006)SecurityMedium
A security engineer wants to harden a server's firewall so that any inbound traffic not explicitly matched by an existing rule is silently discarded, while all currently configured rules remain unchanged. Which command achieves this for the INPUT chain?
- Aiptables -A INPUT -j DROP
- Biptables -N INPUT DROP
- Ciptables -P INPUT DROP
- Diptables -F INPUT
Show answer & explanationAnswer & explanation
Correct answer: C. iptables -P INPUT DROP
iptables -P INPUT DROP sets the default (chain) policy for INPUT to DROP, meaning any packet not matched by an explicit rule falls through to this policy. Appending a DROP rule with -A could interfere with rule ordering, while -F flushes rules and -N creates a new custom chain.
Why the other options are wrong
- A. Appending a rule places DROP at the end of the chain, but it is a rule, not the chain's default policy, and ordering matters for later additions.
- B. -N creates a new user-defined chain; it cannot set a policy for the built-in INPUT chain and INPUT already exists.
- D. -F flushes (deletes) all rules in the INPUT chain, which is destructive and not what's requested.
iptables Default Chain Policy
The -P flag sets the default action (ACCEPT or DROP) applied to packets that don't match any rule in a built-in chain (INPUT, OUTPUT, FORWARD).
- iptables -P INPUT DROP sets default policy to DROP
- Only built-in chains (INPUT/OUTPUT/FORWARD) support -P
- -A appends a rule; it does not change the chain policy
- -F flushes all rules but leaves the policy unchanged
Memory trick: '-P' = the Policy gatekeeper standing at the end of the chain.