hardMultiple Choice
SSCP Practice Question: Refer to the exhibit
Network Topology
Refer to the exhibit. A security analyst reviews these iptables rules and expects SSH access to be blocked, but it is still allowed. What is the MOST likely reason?
⚠ Common exam trap
Many candidates assume iptables evaluates all rules and applies the most restrictive one, but in reality, iptables uses first-match logic, so rule order is critical.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ACCEPT rule matches before the DROP rule.
C is correct because iptables processes rules in sequential order, and the first matching rule determines the packet's fate. In this scenario, the ACCEPT rule for SSH (typically matching on port 22) appears before the DROP rule in the chain, so incoming SSH packets match the ACCEPT rule first and are permitted, never reaching the subsequent DROP rule. This is a classic ordering issue where a more specific allow rule precedes a general deny rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DROP rule does not apply to SSH.
Why it's wrong here
The DROP rule matches by port or protocol; if SSH traffic still passes, the rule likely sits after an earlier ACCEPT, or matches a different port, protocol or chain than the SSH packets traverse. A DROP rule targeting SSH would block it when correctly ordered and matched.
- ✗
The DROP rule is misconfigured with wrong source.
Why it's wrong here
A wrong source in the DROP rule would leave SSH unmatched, but the exhibit's rule matches the analyst's traffic, so this does not explain the observed allow. Source-scoped DROP rules are the right choice when blocking a specific host or subnet rather than all SSH.
- ✓
The ACCEPT rule matches before the DROP rule.
Why this is correct
iptables evaluates rules sequentially within a chain and stops at the first match. If a permissive ACCEPT rule for SSH appears above the DROP rule, traffic is accepted before the DROP is ever evaluated, so ordering, not rule logic, causes the block to fail.
- ✗
The default policy allows traffic, overriding the DROP rule.
Why it's wrong here
A default ACCEPT policy only applies when no rule matches; the SSH packet still traverses the INPUT chain, so a matching DROP would take effect. The real cause is rule ordering or interface/source mismatch. Default policies are correctly set to DROP as a hardening baseline, which is why this distractor appeals.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.