CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security engineer is tasked with hardening a critical Linux server that processes sensitive financial data. The organization's policy dictates that the server must only allow outbound connections to a specific set of whitelisted IP addresses and ports, and all other outbound traffic must be denied by default. Additionally, inbound connections should only be allowed for SSH (port 22) from a management subnet. Which Linux tool is the MOST appropriate for configuring these network filtering rules?
- AAppArmor
- Biptables
- Csystemd-networkd
- DSELinux
Show answer & explanationAnswer & explanation
Correct answer: B. iptables
iptables is the standard Linux command-line utility for configuring the kernel firewall. It allows for highly granular control over incoming and outgoing network traffic, making it ideal for implementing the specified whitelisting and blacklisting rules for both inbound and outbound connections based on IP addresses and ports.
Why the other options are wrong
- A. AppArmor is another mandatory access control system that confines programs to a limited set of resources, but it's not primarily for network packet filtering.
- C. systemd-networkd is a system daemon that manages network interfaces and configurations, not for firewall rules.
- D. SELinux (Security-Enhanced Linux) is a mandatory access control security mechanism that controls process and file access, not network packet filtering.
iptables
A command-line utility for configuring the Linux kernel firewall (Netfilter). It allows administrators to define rules for packet filtering, Network Address Translation (NAT), and other packet manipulation.
- Linux kernel firewall configuration tool.
- Controls inbound and outbound network traffic.
- Uses chains (INPUT, OUTPUT, FORWARD) and rules.
Memory trick: IPTABLES puts a TABLE of rules to filter IP packets.