Courseiva
Networking →hardMultiple Choice

LFCS Networking Practice Question

An administrator needs to allow incoming SSH connections on port 22 from the 192.168.50.0/24 subnet while blocking all other incoming SSH traffic, without disrupting existing established connections. Which command sequence using nftables accomplishes this?

⚠ Common exam trap

The trap here is assuming that nftables reorders rules or that a later accept can override an earlier drop; rule order is strictly sequential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop

nftables evaluates rules in the order they appear within a chain. To allow a specific source and block the rest, the accept rule for that source must precede the drop rule for the port. Reversing the order or inverting the match conditions produces the opposite of the desired policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop

    Why this is correct

    The first rule accepts SSH from the specified subnet, and the second drops all other SSH traffic. Because rules are evaluated in order, allowed sources match the accept rule before reaching the drop rule. Established connections are unaffected if the input chain already accepts them earlier.

  • ✗

    nft add rule inet filter input tcp dport 22 drop; nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept

    Why it's wrong here

    Placing the drop rule first means all SSH packets are dropped before the accept rule is evaluated. The subnet would never be allowed, and the order makes the accept rule unreachable for SSH traffic, breaking the intended access.

  • ✗

    nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 drop; nft add rule inet filter input tcp dport 22 accept

    Why it's wrong here

    This reverses the intended logic: it drops SSH from the allowed subnet and accepts SSH from everywhere else. That is the opposite of the requirement and would lock out the intended clients while opening the service to all others.

  • ✗

    nft add rule inet filter input ip saddr 192.168.50.0/24 tcp dport 22 accept; nft add rule inet filter input tcp dport 22 reject

    Why it's wrong here

    Using reject instead of drop sends TCP RST or ICMP unreachable messages back to disallowed clients. While functionally restrictive, the scenario asks to block traffic; reject is a different behavior and may not be desired for stealth or compliance reasons.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This LFCS question is part of Courseiva's 406-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.