Courseiva
Networking →hardMultiple Choice

LFCS Networking Practice Question

An administrator is diagnosing a Linux router that forwards packets between two internal subnets. Users on 10.20.30.0/24 can reach hosts on 10.20.40.0/24, but responses from 10.20.40.0/24 arrive with the router's external address as the source. The administrator wants to inspect the NAT rules without modifying them. Which command displays the current rules in the nat table with packet and byte counters?

⚠ Common exam trap

The trap here is forgetting that iptables defaults to the filter table, so omitting -t nat silently shows the wrong set of chains and hides all NAT rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables -t nat -L -n -v

The nat table holds the PREROUTING, OUTPUT, and POSTROUTING chains where SNAT, DNAT, and MASQUERADE rules live. To inspect them with hit counters, iptables must be invoked with -t nat and the verbose flag -v, plus -n to avoid DNS lookups. This gives a clear picture of which rule is rewriting source addresses on the return path, without altering any rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    iptables -t nat -L -n -v

    Why this is correct

    This lists all chains in the nat table, shows numeric addresses and ports with -n, and includes packet and byte counters with -v. It is read-only, so it satisfies the requirement to inspect without modifying. The output shows the PREROUTING, INPUT, OUTPUT, and POSTROUTING chains with their rules and hit counts, which is exactly what is needed to confirm which NAT rule is rewriting source addresses.

  • ✗

    nft list ruleset

    Why it's wrong here

    On a system using iptables-nft, this would show the translated rules, but the question specifies inspecting iptables NAT rules with counters. nft list ruleset does not display per-rule packet and byte counters unless the counters are explicitly included, and on legacy iptables systems it would show nothing. It is not the precise command for the stated goal.

  • ✗

    iptables -L -n -v

    Why it's wrong here

    Without -t nat, iptables defaults to the filter table, which contains INPUT, FORWARD, and OUTPUT chains for packet filtering, not NAT rules. The administrator would see ACCEPT/DROP rules but no MASQUERADE or SNAT entries, so the source-rewriting behavior would not be visible. This command answers a different question than the one asked.

  • ✗

    iptables -t nat -S

    Why it's wrong here

    The -S option prints the rules in a format that can be fed back to iptables-restore. While it does show the nat table rules, it does not display packet and byte counters, so the administrator cannot see which rules are actually matching traffic. It is useful for backup or migration, but not for the diagnostic requirement here.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.