問題文
A rule at the address level drops traffic from a subnet, yet traffic from that subnet is still being carried through the system. What explains it?
選択肢
- The rules are read after the ones that the system supplies for itself, since a rule that the system supplies allows the traffic of every service that it runs.
- The rules are held in a pending state until the next set is put into force, since a change on one interface waits for the other one.
- The rules reach only the traffic that is fresh and inbound, since the reply to a connection raised from the inside is taken in whatever the rules say.
- The rules leave the traffic of the interface that carries the second network alone, since a rule of this kind is drawn up for one interface and not for the pair.