Courseiva
Networking →mediumMultiple Choice

LFCS Networking Practice Question

A network administrator needs to block all incoming SSH traffic (port 22) from the 192.168.2.0/24 subnet. Which iptables command accomplishes this?

⚠ Common exam trap

Test-takers frequently confuse the -s and -d flags, or mistakenly apply the rule to the OUTPUT chain, thinking they need to block outgoing responses rather than incoming connection attempts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables -A INPUT -s 192.168.2.0/24 -p tcp --dport 22 -j DROP

It appends a rule to the INPUT chain that matches packets originating from the 192.168.2.0/24 subnet (-s 192.168.2.0/24) using TCP protocol with destination port 22 (--dport 22), and then drops them (-j DROP). This precisely blocks all incoming SSH traffic from that subnet while leaving other traffic unaffected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    iptables -A INPUT -d 192.168.2.0/24 -p tcp --dport 22 -j DROP

    Why it's wrong here

    -d specifies destination, not source; this would drop traffic destined to that subnet.

  • ✗

    iptables -A OUTPUT -d 192.168.2.0/24 -p tcp --sport 22 -j DROP

    Why it's wrong here

    The OUTPUT chain filters locally generated packets, so this rule never inspects inbound SSH arriving from 192.168.2.0/24; it would instead drop replies sourced from port 22 leaving the host. OUTPUT suits restricting outbound connections a server initiates, such as blocking its own SSH client traffic to that subnet.

  • ✗

    iptables -A INPUT -s 192.168.2.0/24 -j DROP

    Why it's wrong here

    Dropping every packet sourced from 192.168.2.0/24 blocks all protocols, not just SSH on port 22, breaking unrelated services the subnet legitimately uses. Adding -p tcp --dport 22 restricts the rule to the SSH traffic the scenario specifies.

  • ✓

    iptables -A INPUT -s 192.168.2.0/24 -p tcp --dport 22 -j DROP

    Why this is correct

    Appending a rule to the INPUT chain with `-s 192.168.2.0/24` matches the source subnet, `-p tcp --dport 22` targets SSH, and `-j DROP` silently discards matching packets, satisfying the requirement to block all incoming SSH from that subnet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.