nftables supports set-based matching. The syntax 'tcp dport { 22, 80 } accept' matches packets with destination port 22 or 80 and accepts them. This is efficient and concise, reducing the number of rules. It is a valid and recommended way to allow multiple ports.
Why this answer
To filter incoming traffic with nftables, you must create a base chain with type filter and hook input. Allowing multiple ports can be done with a set in a single rule. The default policy should be drop to block other traffic, and connection tracking handles return traffic without output rules.
Rules are not persistent unless saved and loaded at boot.
Exam trap
The trap here is assuming nftables rules persist automatically or that output rules are needed for return traffic, when conntrack handles it and persistence requires saving.