Courseiva
Security →hardMultiple Select

XK0-006 Security Practice Question

An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)

⚠ Common exam trap

The trap is selecting a rule that allows SSH from any source (Option D) instead of restricting to the required subnet, or confusing FORWARD policy with INPUT/OUTPUT policies; candidates must read the source restriction carefully.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables -A INPUT -p tcp --dport 22 -s 192.168.1.0/24 -j ACCEPT

Option A is correct because it appends an INPUT rule that matches TCP packets destined for port 22 (--dport 22) with source address 192.168.1.0/24 (-s 192.168.1.0/24) and accepts them, exactly fulfilling the requirement to allow SSH only from that subnet. Option B is correct because setting the OUTPUT chain's default policy to ACCEPT (iptables -P OUTPUT ACCEPT) permits all outgoing traffic, matching the stated requirement. Option E is correct because setting the INPUT chain's default policy to DROP (iptables -P INPUT DROP) ensures that any incoming traffic not explicitly accepted by the earlier SSH rule is dropped, satisfying the 'drop all other incoming traffic' requirement. Option C is not correct because FORWARD concerns traffic routed through the host, not traffic destined to the server itself, and the scenario does not require allowing forwarded packets. Option D is not correct because it accepts SSH from any source address, not restricted to 192.168.1.0/24 as required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    iptables -A INPUT -p tcp --dport 22 -s 192.168.1.0/24 -j ACCEPT

    Why this is correct

    This rule appends to the INPUT chain, matching TCP destination port 22 with source 192.168.1.0/24 and accepting it. It satisfies the requirement to permit SSH only from that subnet, and must precede the blanket INPUT drop so legitimate SSH is not discarded.

  • ✓

    iptables -P OUTPUT ACCEPT

    Why this is correct

    Setting the OUTPUT chain's default policy to ACCEPT permits all outbound traffic without per-rule matching, satisfying the requirement to allow all outgoing traffic. As a policy rather than an appended rule, it applies to any packet leaving the host that no specific rule handles.

  • ✗

    iptables -P FORWARD ACCEPT

    Why it's wrong here

    The FORWARD chain governs traffic routed through the host, not traffic destined for it, so this policy leaves inbound INPUT filtering undefined. It is tempting because ACCEPT policies are commonly set on FORWARD for routers and NAT gateways, where transit traffic genuinely needs permitting.

  • ✗

    iptables -A INPUT -p tcp --dport 22 -j ACCEPT

    Why it's wrong here

    Allowing port 22 without a source restriction accepts SSH from any address, not just 192.168.1.0/24, so it fails the stated requirement. It is tempting because a bare port-22 ACCEPT rule is exactly what you would write when SSH must be reachable from every host, such as an internet-facing bastion.

  • ✓

    iptables -P INPUT DROP

    Why this is correct

    Setting the INPUT chain's default policy to DROP discards every inbound packet lacking an explicit ACCEPT rule, satisfying the requirement to drop all other incoming traffic. The earlier SSH rule must precede it logically, since policy applies only after rules are evaluated.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.