LPIC-1 Essential System Services and Networking Practice Question
A Linux server uses nftables as its firewall. The administrator needs to allow incoming SSH (TCP/22) and HTTP (TCP/80) while dropping all other incoming traffic. Which TWO statements about implementing this are correct? (Choose two.)
⚠ Common exam trap
The trap here is assuming nftables rules persist automatically or that output rules are needed for return traffic, when conntrack handles it and persistence requires saving.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.
To filter incoming traffic with nftables, you must create a base chain with type filter and hook input. Allowing multiple ports can be done with a set in a single rule. The default policy should be drop to block other traffic, and connection tracking handles return traffic without output rules. Rules are not persistent unless saved and loaded at boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rules must be added to the output chain to allow responses from the server to clients.
Why it's wrong here
In nftables, connection tracking (conntrack) allows return traffic for established connections automatically if the input chain accepts the initial packet. Adding rules to the output chain is unnecessary for allowing responses to inbound SSH and HTTP connections. The output chain would only be needed for outbound-initiated traffic.
- ✓
The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.
Why this is correct
nftables supports set-based matching. The syntax 'tcp dport { 22, 80 } accept' matches packets with destination port 22 or 80 and accepts them. This is efficient and concise, reducing the number of rules. It is a valid and recommended way to allow multiple ports.
- ✓
A base chain must be created with type filter and hook input to process incoming packets.
Why this is correct
In nftables, a base chain is required to hook into the netfilter pipeline. For incoming traffic, the chain must have type filter and hook input. Without this, rules will not be evaluated for incoming packets. This is a fundamental step to enforce any filtering policy on incoming connections.
- ✗
The default policy of the input chain must be set to accept to allow the specified ports.
Why it's wrong here
Setting the default policy to accept would allow all traffic that does not match any rule, which contradicts the requirement to drop all other incoming traffic. Instead, the policy should be drop, and explicit accept rules for SSH and HTTP should be added before the drop policy takes effect.
- ✗
The command 'nft add rule ip filter input tcp dport 22 accept' will persist across reboots by default.
Why it's wrong here
nftables rules added via the nft command are not persistent across reboots unless saved to a configuration file (e.g., /etc/nftables.conf) and loaded by the nftables.service. The command alone only modifies the running ruleset. Persistence requires explicit saving and enabling the service.
Visual reference
Go deeper
Related to this question
About these practice questions
This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official LPI exam blueprint
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.