CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security auditor is reviewing the hardening configuration of a Linux server that hosts a critical web application. The auditor needs to verify that the server is configured to drop network packets that do not match any established connection and to block traffic from specific malicious IP addresses identified in threat intelligence feeds. Which command-line utility should the auditor focus on examining to confirm these firewall rules?
- Aroute
- Bnetstat
- Css
- Diptables
Show answer & explanationAnswer & explanation
Correct answer: D. iptables
The `iptables` utility (or its successor `nftables`) is the standard Linux command-line tool for configuring the kernel's packet filtering firewall. It is used to define rules for dropping unmatched packets and blocking traffic from specific IP addresses, directly addressing the auditor's requirements.
Why the other options are wrong
- A. `route` displays and manipulates the IP routing table, but it does not configure packet filtering (firewall) rules.
- B. `netstat` displays network connections, routing tables, and interface statistics, but does not configure firewall rules.
- C. `ss` (socket statistics) is similar to `netstat` but provides more detailed socket information; it does not configure firewall rules.
iptables
iptables is a user-space utility program that allows a system administrator to configure the IP packet filter rules of the Linux kernel firewall.
- Manages packet filtering rules (chains, tables).
- Used for network address translation (NAT), port forwarding, stateful inspection.
- Essential for Linux server hardening and network segmentation.
Memory trick: iptables is the gatekeeper for Linux network traffic.