Courseiva
Troubleshooting →mediumMultiple Choice

XK0-006 Troubleshooting Practice Question

A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that packets are being dropped due to a misconfigured firewall rule. Which command should the administrator use to view the current iptables rules and their packet counters?

⚠ Common exam trap

The trap here is assuming that network capture tools like tcpdump can show firewall rule counters; they capture packets but do not display iptables rule statistics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables -L -v -n

To diagnose firewall-related packet drops, the administrator needs to see the iptables rules along with their match counters. The `iptables -L -v -n` command provides a verbose listing with packet and byte counts, and numeric output. This reveals which rules are being hit and can indicate if a drop rule is matching traffic. Other commands either modify the firewall or show unrelated information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tcpdump -i eth0

    Why it's wrong here

    `tcpdump -i eth0` captures and displays network packets on the eth0 interface, which can show traffic but not the firewall rules themselves. While it can indicate if packets are arriving or leaving, it does not directly show which iptables rule is dropping them. It is useful for packet analysis but not for viewing firewall configuration and counters.

  • ✗

    iptables -F

    Why it's wrong here

    `iptables -F` flushes all rules from the chains, effectively removing all firewall filtering. This would not help diagnose the issue; it would disable the firewall entirely, potentially exposing the server. It also does not display any information about current rules or counters. Flushing rules is a destructive action that should not be used for troubleshooting without careful consideration.

  • ✗

    netstat -tuln

    Why it's wrong here

    `netstat -tuln` lists listening TCP and UDP ports with numeric addresses, but it does not show firewall rules or packet counters. It can help identify which services are listening, but it cannot reveal if iptables is dropping packets. Therefore, it is not the right tool for diagnosing firewall-related connectivity issues.

  • ✓

    iptables -L -v -n

    Why this is correct

    The `iptables -L -v -n` command lists all rules in the current chains with verbose output (`-v`) showing packet and byte counters, and `-n` displays IP addresses and ports numerically to avoid DNS lookups. This allows the administrator to see which rules are matching traffic and potentially dropping packets. The counters are essential for identifying if a specific rule is blocking legitimate traffic.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.