LFCS Networking Practice Question
An administrator is diagnosing a Linux router that forwards packets between two internal subnets. Users on 10.20.30.0/24 can reach hosts on 10.20.40.0/24, but responses from 10.20.40.0/24 arrive with the router's external address as the source. The administrator wants to inspect the NAT rules without modifying them. Which command displays the current rules in the nat table with packet and byte counters?
⚠ Common exam trap
The trap here is forgetting that iptables defaults to the filter table, so omitting -t nat silently shows the wrong set of chains and hides all NAT rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
iptables -t nat -L -n -v
The nat table holds the PREROUTING, OUTPUT, and POSTROUTING chains where SNAT, DNAT, and MASQUERADE rules live. To inspect them with hit counters, iptables must be invoked with -t nat and the verbose flag -v, plus -n to avoid DNS lookups. This gives a clear picture of which rule is rewriting source addresses on the return path, without altering any rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
iptables -t nat -L -n -v
Why this is correct
This lists all chains in the nat table, shows numeric addresses and ports with -n, and includes packet and byte counters with -v. It is read-only, so it satisfies the requirement to inspect without modifying. The output shows the PREROUTING, INPUT, OUTPUT, and POSTROUTING chains with their rules and hit counts, which is exactly what is needed to confirm which NAT rule is rewriting source addresses.
- ✗
nft list ruleset
Why it's wrong here
On a system using iptables-nft, this would show the translated rules, but the question specifies inspecting iptables NAT rules with counters. nft list ruleset does not display per-rule packet and byte counters unless the counters are explicitly included, and on legacy iptables systems it would show nothing. It is not the precise command for the stated goal.
- ✗
iptables -L -n -v
Why it's wrong here
Without -t nat, iptables defaults to the filter table, which contains INPUT, FORWARD, and OUTPUT chains for packet filtering, not NAT rules. The administrator would see ACCEPT/DROP rules but no MASQUERADE or SNAT entries, so the source-rewriting behavior would not be visible. This command answers a different question than the one asked.
- ✗
iptables -t nat -S
Why it's wrong here
The -S option prints the rules in a format that can be fed back to iptables-restore. While it does show the nat table rules, it does not display packet and byte counters, so the administrator cannot see which rules are actually matching traffic. It is useful for backup or migration, but not for the diagnostic requirement here.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.