XK0-006 nftables rule syntax Practice Question
A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.
⚠ Common exam trap
The trap here is that candidates pick 'insert' or a plain drop rule without the source negation, forgetting that nftables is first-match-wins and that dropping all SSH would lock out the management network — the exam tests whether you read the requirement to exclude the management subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop
The correct rule uses 'nft add rule' with a source address negation (ip saddr != 192.168.1.0/24) matching TCP destination port 22 and a drop verdict, which precisely drops SSH from every source outside the management network while leaving the existing allow rule intact. This is the only option that combines the correct match criteria (source negation plus SSH port) with the drop action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop
Why this is correct
The rule matches source addresses outside 192.168.1.0/24 on TCP port 22 and drops them, satisfying the requirement to block non-management SSH. Using '!=' with the saddr match and the drop verdict enforces the restriction within the inet filter input chain.
- ✗
nft insert rule inet filter input tcp dport 22 drop
Why it's wrong here
This inserts a drop rule at the top of the chain, so it matches before the existing management-network accept rule, blocking SSH from 192.168.1.0/24 too. Appending the drop after the accept rule would be correct, since nftables evaluates rules in order.
- ✗
nft replace rule inet filter input handle 1 tcp dport 22 drop
Why it's wrong here
Replace overwrites an existing rule identified by handle, so it modifies the current SSH rule rather than adding a new drop for other sources. Replace is correct when amending a specific known rule, not when inserting an additional drop condition alongside the existing accept.
- ✗
nft add rule inet filter input tcp dport 22 accept
Why it's wrong here
This accepts SSH from every source, including outside 192.168.1.0/24, so it widens access rather than restricting it. It is tempting because accepting tcp dport 22 is the standard rule for permitting SSH; it would be correct when the goal is to enable management access, not to drop it.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
Key term
nftables
nftables is a modern Linux kernel packet classification framework that replaces the older iptables, ip6tables, arptables, and ebtables tools for configuring network packet filtering, NAT, and firewall rules.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.