CompTIA Linux+ (XK0-006)SecurityHard

A junior administrator is configuring a new Linux server and needs to enable kernel-level packet filtering with nftables. After installing the 'nftables' package, which command would be used to create a basic 'filter' table with an 'input' chain that drops all incoming traffic by default?

  1. Anft add table ip filter; nft add chain ip filter input { type filter hook input priority 0; policy drop; }
  2. Bnft add chain ip filter input { hook input type filter priority 0; policy drop; }
  3. Cnft add table filter; nft add chain filter input { type filter hook input priority 0; policy drop; }
  4. Dnft add table ip filter; nft add chain ip filter input { type filter hook input priority 0; policy reject; }
Show answer & explanation

Correct answer: A. nft add table ip filter; nft add chain ip filter input { type filter hook input priority 0; policy drop; }

The correct nftables syntax requires creating the 'ip filter' table first, then adding the 'input' chain to it. The chain definition must specify the type (filter), the hook (input), a priority, and the default policy (drop). Option A correctly sequences these steps and uses the proper syntax for both creating the table and the chain with a 'drop' policy.

Why the other options are wrong

  • B. This command attempts to add a chain without first explicitly creating the 'ip filter' table, which is required. It also misses the initial 'nft add table ip filter' step.
  • C. This command incorrectly omits the 'ip' family when creating the table and chain, assuming a default which is not always the case or best practice for clarity. 'nft add table filter' is ambiguous without a family.
  • D. While syntactically mostly correct, using 'policy reject' sends an ICMP error message back to the sender, which is generally not as secure as 'drop' for a default policy as it reveals the host exists.

nftables Chain Policy

In nftables, a chain policy defines the default action for packets that traverse a chain and do not match any specific rules within that chain. Common policies are 'accept' (allow) and 'drop' (discard silently).

  • Set when defining or updating a chain (e.g., 'policy drop;').
  • Crucial for security, as it dictates default behavior.
  • 'drop' discards packets silently, 'reject' sends an error message back.

Memory trick: Tables hold Chains, Chains hold Rules, all with a Family.

More Security questions