LPIC-1 Essential System Services and Networking Practice Question
Network Topology
A web server running on this host is not accessible from clients. Based on the exhibit, what is the most likely reason?
⚠ Common exam trap
Many exam-takers confuse the FORWARD chain with the INPUT chain, assuming that blocking traffic to a local service requires a FORWARD rule, when in fact the INPUT chain governs packets destined for the host itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incoming HTTP traffic is blocked by a DROP rule on port 80.
The exhibit shows a firewall rule set where the INPUT chain has a DROP rule for destination port 80 (HTTP). Since incoming HTTP traffic from clients must traverse the INPUT chain to reach the local web server process, this DROP rule explicitly blocks all inbound HTTP requests, making the web server inaccessible. The FORWARD chain is irrelevant because traffic destined for the local host uses the INPUT chain, not FORWARD.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FORWARD chain policy is DROP.
Why it's wrong here
The FORWARD chain handles traffic routed through the host, not traffic destined for its own local web server, which traverses the INPUT chain. It is tempting because a DROP policy blocks packets, but only for forwarded traffic, so local inbound requests remain governed by INPUT.
- ✗
The OUTPUT chain policy is ACCEPT.
Why it's wrong here
An ACCEPT policy on the OUTPUT chain governs locally generated outbound traffic, not inbound client requests arriving at the web server. It tempts because permissive OUTPUT policies are common hardening oversights, and would matter if the host itself initiated connections that were being dropped.
- ✓
Incoming HTTP traffic is blocked by a DROP rule on port 80.
Why this is correct
A DROP rule on port 80 silently discards inbound HTTP packets before the web server can respond, which matches the exhibit showing no listener reachability from clients. Because DROP gives no rejection response, clients time out rather than receive a connection refused error, confirming the firewall as the blocking constraint.
- ✗
SSH traffic is blocked.
Why it's wrong here
SSH blocking affects remote administration on port 22 and has no bearing on HTTP or HTTPS reachability from clients. It is tempting because a blocked port is a common cause of connectivity failure, and it would be correct if the exhibit showed the administrator unable to log in remotely.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.