CompTIA SecurityX (CAS-005)Security EngineeringEasy
A security engineer is hardening a critical Linux server that hosts a proprietary application. To prevent unauthorized access and exfiltration, the engineer needs to limit the server's outbound network connections to only specific, approved IP addresses and ports required by the application. Which command-line utility is BEST suited for configuring these packet filtering rules directly on the Linux kernel?
- Ass
- Biptables
- Croute
- Dnetstat
Show answer & explanationAnswer & explanation
Correct answer: B. iptables
iptables is the standard command-line utility for configuring the Linux kernel's netfilter firewall. It allows granular control over incoming, outgoing, and forwarded network packets, enabling the engineer to precisely define rules for permitted outbound connections based on IP address and port.
Why the other options are wrong
- A. ss (socket statistics) is similar to netstat but provides more detailed socket information; it does not configure firewall rules.
- C. route is used to view and manipulate the IP routing table, not to set packet filtering rules.
- D. netstat displays network connections, routing tables, and interface statistics, but does not configure firewall rules.
iptables
A command-line utility used to configure the Linux kernel's netfilter firewall, allowing granular control over network packet filtering and manipulation.
- Configures netfilter firewall in Linux
- Manages packet filtering rules (INPUT, OUTPUT, FORWARD chains)
- Controls network traffic based on IP, port, protocol
Memory trick: IPTables: I Prevent Traffic that's not Allowed, Blocking Every Source!