LFCS Networking Practice Question
An administrator needs to allow incoming SSH connections on port 22 from the 192.168.50.0/24 subnet while blocking all other incoming SSH traffic, without disrupting existing established connections. Which command sequence using nftables accomplishes this?
⚠ Common exam trap
The trap here is assuming that nftables reorders rules or that a later accept can override an earlier drop; rule order is strictly sequential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop
nftables evaluates rules in the order they appear within a chain. To allow a specific source and block the rest, the accept rule for that source must precede the drop rule for the port. Reversing the order or inverting the match conditions produces the opposite of the desired policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop
Why this is correct
The first rule accepts SSH from the specified subnet, and the second drops all other SSH traffic. Because rules are evaluated in order, allowed sources match the accept rule before reaching the drop rule. Established connections are unaffected if the input chain already accepts them earlier.
- ✗
nft add rule inet filter input tcp dport 22 drop; nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept
Why it's wrong here
Placing the drop rule first means all SSH packets are dropped before the accept rule is evaluated. The subnet would never be allowed, and the order makes the accept rule unreachable for SSH traffic, breaking the intended access.
- ✗
nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 drop; nft add rule inet filter input tcp dport 22 accept
Why it's wrong here
This reverses the intended logic: it drops SSH from the allowed subnet and accepts SSH from everywhere else. That is the opposite of the requirement and would lock out the intended clients while opening the service to all others.
- ✗
nft add rule inet filter input ip saddr 192.168.50.0/24 tcp dport 22 accept; nft add rule inet filter input tcp dport 22 reject
Why it's wrong here
Using reject instead of drop sends TCP RST or ICMP unreachable messages back to disallowed clients. While functionally restrictive, the scenario asks to block traffic; reject is a different behavior and may not be desired for stealth or compliance reasons.
Visual reference
Go deeper
Related to this question
About these practice questions
This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.