XK0-006 Troubleshooting Practice Question
A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that packets are being dropped due to a misconfigured firewall rule. Which command should the administrator use to view the current iptables rules and their packet counters?
⚠ Common exam trap
The trap here is assuming that network capture tools like tcpdump can show firewall rule counters; they capture packets but do not display iptables rule statistics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
iptables -L -v -n
To diagnose firewall-related packet drops, the administrator needs to see the iptables rules along with their match counters. The `iptables -L -v -n` command provides a verbose listing with packet and byte counts, and numeric output. This reveals which rules are being hit and can indicate if a drop rule is matching traffic. Other commands either modify the firewall or show unrelated information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tcpdump -i eth0
Why it's wrong here
`tcpdump -i eth0` captures and displays network packets on the eth0 interface, which can show traffic but not the firewall rules themselves. While it can indicate if packets are arriving or leaving, it does not directly show which iptables rule is dropping them. It is useful for packet analysis but not for viewing firewall configuration and counters.
- ✗
iptables -F
Why it's wrong here
`iptables -F` flushes all rules from the chains, effectively removing all firewall filtering. This would not help diagnose the issue; it would disable the firewall entirely, potentially exposing the server. It also does not display any information about current rules or counters. Flushing rules is a destructive action that should not be used for troubleshooting without careful consideration.
- ✗
netstat -tuln
Why it's wrong here
`netstat -tuln` lists listening TCP and UDP ports with numeric addresses, but it does not show firewall rules or packet counters. It can help identify which services are listening, but it cannot reveal if iptables is dropping packets. Therefore, it is not the right tool for diagnosing firewall-related connectivity issues.
- ✓
iptables -L -v -n
Why this is correct
The `iptables -L -v -n` command lists all rules in the current chains with verbose output (`-v`) showing packet and byte counters, and `-n` displays IP addresses and ports numerically to avoid DNS lookups. This allows the administrator to see which rules are matching traffic and potentially dropping packets. The counters are essential for identifying if a specific rule is blocking legitimate traffic.
Go deeper
Related to this question
Learn chapter
Firewall and Security Basics
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.