LFCS Networking Practice Question
Which THREE are built-in chains in the iptables filter table? (Choose three.)
⚠ Common exam trap
Watch out — candidates often confuse the filter table's chains with those of the nat table (PREROUTING, POSTROUTING) because all chains are used in packet traversal, but only INPUT, OUTPUT, and FORWARD belong to the filter table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
INPUT
The filter table in iptables is used for packet filtering decisions based on IP addresses, ports, and protocols. Its built-in chains are INPUT (for packets destined for the local system), OUTPUT (for packets originating from the local system), and FORWARD (for packets routed through the system). These three chains allow you to control traffic at different points in the packet flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
POSTROUTING
Why it's wrong here
POSTROUTING belongs to the nat table, which rewrites source addresses on outbound packets; the filter table's built-in chains are INPUT, FORWARD and OUTPUT. It is tempting because POSTROUTING is a genuine iptables chain, making it the correct choice when configuring NAT or masquerading, but it is not part of filter.
- ✓
INPUT
Why this is correct
INPUT is one of the three built-in chains of the iptables filter table, alongside FORWARD and OUTPUT. It processes packets destined for the local host itself, satisfying the stem's requirement for a built-in filter chain rather than a user-defined one.
- ✓
OUTPUT
Why this is correct
OUTPUT is one of the three built-in chains in the iptables filter table, handling packets generated locally by the host before they leave. The other two are INPUT and FORWARD, so OUTPUT correctly satisfies the question's requirement for a built-in filter chain.
- ✓
FORWARD
Why this is correct
FORWARD is one of the three built-in chains of the iptables filter table, alongside INPUT and OUTPUT. It processes packets routed through the host rather than delivered locally or generated locally, satisfying the stem's requirement for a built-in filter chain.
- ✗
PREROUTING
Why it's wrong here
PREROUTING belongs to the nat and mangle tables, not filter; it handles destination NAT before routing decisions. It is tempting because it is a genuine built-in iptables chain, but the filter table's built-ins are INPUT, FORWARD and OUTPUT.
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.