CompTIA SecurityX (CAS-005)Security EngineeringEasy

A security engineer is hardening a critical Linux server that hosts a proprietary application. The requirement is to restrict network access to the server based on specific IP addresses and port numbers, and to enforce stateful packet filtering for established connections. Which command-line utility is BEST suited for configuring these firewall rules?

  1. Aroute
  2. Biptables
  3. Cnetstat
  4. Dss
Show answer & explanation

Correct answer: B. iptables

iptables is the traditional command-line utility for configuring the Linux kernel firewall (netfilter). It allows for highly granular control over packet filtering, including specifying source/destination IPs, port numbers, and stateful inspection of connections, directly meeting the described requirements.

Why the other options are wrong

  • A. route is used to view and manipulate the IP routing table, not to configure packet filtering firewall rules.
  • C. netstat displays network connections, routing tables, and interface statistics, but it does not configure firewall rules.
  • D. ss (socket statistics) is similar to netstat but provides more detailed information about sockets, not firewall configuration.

iptables

A command-line utility that allows system administrators to configure the IP packet filter rules of the Linux kernel firewall (netfilter).

  • Manages packet filtering rules (INPUT, OUTPUT, FORWARD chains)
  • Supports stateful packet inspection
  • Can filter by IP, port, protocol, and more

Memory trick: iptables: Your Linux server's personal bouncer, deciding who gets in and out.

More Security Engineering questions