CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is hardening a critical Linux server that hosts a proprietary application. As part of the hardening process, the engineer needs to restrict network access to only essential services, specifically SSH (port 22) and the application's unique port (TCP 8443) from a limited set of administrative IP addresses. All other inbound and outbound traffic should be blocked by default. Which command-line utility is BEST suited for implementing these granular packet filtering rules directly on the Linux server?

  1. Anetstat
  2. Btcpdump
  3. Ciptables
  4. Dfirewalld
Show answer & explanation

Correct answer: C. iptables

iptables is a powerful command-line utility for configuring the Linux kernel firewall. It allows for highly granular packet filtering rules, including specifying ports, protocols, and source/destination IP addresses, making it ideal for the described hardening scenario.

Why the other options are wrong

  • A. netstat is used to display network connections, routing tables, and interface statistics, not to configure firewall rules.
  • B. tcpdump is a packet analyzer used for capturing and displaying network traffic, not for configuring firewall rules.
  • D. firewalld is a dynamic firewall management tool that uses zones and services, often built on top of nftables/iptables. While it could be used, iptables provides the direct, granular control specified in the question.

iptables

A command-line utility that allows system administrators to configure the IP packet filter rules of the Linux kernel firewall (Netfilter).

  • Manages packet filtering and NAT.
  • Uses chains (INPUT, OUTPUT, FORWARD) and tables (filter, nat, mangle, raw).
  • Rules are processed sequentially.

Memory trick: iptables Intelligently Protects The Access.

More Security Engineering questions