Courseiva

LPIC-1 Essential System Services and Networking Practice Question

A Linux server uses nftables as its firewall. The administrator needs to allow incoming SSH (TCP/22) and HTTP (TCP/80) while dropping all other incoming traffic. Which TWO statements about implementing this are correct? (Choose two.)

⚠ Common exam trap

The trap here is assuming nftables rules persist automatically or that output rules are needed for return traffic, when conntrack handles it and persistence requires saving.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.

To filter incoming traffic with nftables, you must create a base chain with type filter and hook input. Allowing multiple ports can be done with a set in a single rule. The default policy should be drop to block other traffic, and connection tracking handles return traffic without output rules. Rules are not persistent unless saved and loaded at boot.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rules must be added to the output chain to allow responses from the server to clients.

    Why it's wrong here

    In nftables, connection tracking (conntrack) allows return traffic for established connections automatically if the input chain accepts the initial packet. Adding rules to the output chain is unnecessary for allowing responses to inbound SSH and HTTP connections. The output chain would only be needed for outbound-initiated traffic.

  • ✓

    The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.

    Why this is correct

    nftables supports set-based matching. The syntax 'tcp dport { 22, 80 } accept' matches packets with destination port 22 or 80 and accepts them. This is efficient and concise, reducing the number of rules. It is a valid and recommended way to allow multiple ports.

  • ✓

    A base chain must be created with type filter and hook input to process incoming packets.

    Why this is correct

    In nftables, a base chain is required to hook into the netfilter pipeline. For incoming traffic, the chain must have type filter and hook input. Without this, rules will not be evaluated for incoming packets. This is a fundamental step to enforce any filtering policy on incoming connections.

  • ✗

    The default policy of the input chain must be set to accept to allow the specified ports.

    Why it's wrong here

    Setting the default policy to accept would allow all traffic that does not match any rule, which contradicts the requirement to drop all other incoming traffic. Instead, the policy should be drop, and explicit accept rules for SSH and HTTP should be added before the drop policy takes effect.

  • ✗

    The command 'nft add rule ip filter input tcp dport 22 accept' will persist across reboots by default.

    Why it's wrong here

    nftables rules added via the nft command are not persistent across reboots unless saved to a configuration file (e.g., /etc/nftables.conf) and loaded by the nftables.service. The command alone only modifies the running ruleset. Persistence requires explicit saving and enabling the service.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official LPI exam blueprint

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.