Courseiva
Security →hardMultiple Choice

XK0-006 nftables rule syntax Practice Question

A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.

⚠ Common exam trap

The trap here is that candidates pick 'insert' or a plain drop rule without the source negation, forgetting that nftables is first-match-wins and that dropping all SSH would lock out the management network — the exam tests whether you read the requirement to exclude the management subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop

The correct rule uses 'nft add rule' with a source address negation (ip saddr != 192.168.1.0/24) matching TCP destination port 22 and a drop verdict, which precisely drops SSH from every source outside the management network while leaving the existing allow rule intact. This is the only option that combines the correct match criteria (source negation plus SSH port) with the drop action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop

    Why this is correct

    The rule matches source addresses outside 192.168.1.0/24 on TCP port 22 and drops them, satisfying the requirement to block non-management SSH. Using '!=' with the saddr match and the drop verdict enforces the restriction within the inet filter input chain.

  • ✗

    nft insert rule inet filter input tcp dport 22 drop

    Why it's wrong here

    This inserts a drop rule at the top of the chain, so it matches before the existing management-network accept rule, blocking SSH from 192.168.1.0/24 too. Appending the drop after the accept rule would be correct, since nftables evaluates rules in order.

  • ✗

    nft replace rule inet filter input handle 1 tcp dport 22 drop

    Why it's wrong here

    Replace overwrites an existing rule identified by handle, so it modifies the current SSH rule rather than adding a new drop for other sources. Replace is correct when amending a specific known rule, not when inserting an additional drop condition alongside the existing accept.

  • ✗

    nft add rule inet filter input tcp dport 22 accept

    Why it's wrong here

    This accepts SSH from every source, including outside 192.168.1.0/24, so it widens access rather than restricting it. It is tempting because accepting tcp dport 22 is the standard rule for permitting SSH; it would be correct when the goal is to enable management access, not to drop it.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.