Courseiva
Networking →mediumMultiple Select

LFCS Networking Practice Question

Which THREE are built-in chains in the iptables filter table? (Choose three.)

⚠ Common exam trap

Watch out — candidates often confuse the filter table's chains with those of the nat table (PREROUTING, POSTROUTING) because all chains are used in packet traversal, but only INPUT, OUTPUT, and FORWARD belong to the filter table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

INPUT

The filter table in iptables is used for packet filtering decisions based on IP addresses, ports, and protocols. Its built-in chains are INPUT (for packets destined for the local system), OUTPUT (for packets originating from the local system), and FORWARD (for packets routed through the system). These three chains allow you to control traffic at different points in the packet flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    POSTROUTING

    Why it's wrong here

    POSTROUTING belongs to the nat table, which rewrites source addresses on outbound packets; the filter table's built-in chains are INPUT, FORWARD and OUTPUT. It is tempting because POSTROUTING is a genuine iptables chain, making it the correct choice when configuring NAT or masquerading, but it is not part of filter.

  • ✓

    INPUT

    Why this is correct

    INPUT is one of the three built-in chains of the iptables filter table, alongside FORWARD and OUTPUT. It processes packets destined for the local host itself, satisfying the stem's requirement for a built-in filter chain rather than a user-defined one.

  • ✓

    OUTPUT

    Why this is correct

    OUTPUT is one of the three built-in chains in the iptables filter table, handling packets generated locally by the host before they leave. The other two are INPUT and FORWARD, so OUTPUT correctly satisfies the question's requirement for a built-in filter chain.

  • ✓

    FORWARD

    Why this is correct

    FORWARD is one of the three built-in chains of the iptables filter table, alongside INPUT and OUTPUT. It processes packets routed through the host rather than delivered locally or generated locally, satisfying the stem's requirement for a built-in filter chain.

  • ✗

    PREROUTING

    Why it's wrong here

    PREROUTING belongs to the nat and mangle tables, not filter; it handles destination NAT before routing decisions. It is tempting because it is a genuine built-in iptables chain, but the filter table's built-ins are INPUT, FORWARD and OUTPUT.

About these practice questions

One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.