CompTIA A+ Core 2 (220-1202)SecurityMedium
A small business is setting up a new point-of-sale (POS) system. The IT administrator wants to ensure that the POS terminal can only access the necessary network resources (e.g., payment gateway, inventory server) and is prevented from communicating with other internal network segments or unauthorized external sites. Which network security feature should be configured on the network device connecting the POS terminal?
- ADNS server
- BFirewall rules
- CDHCP server
- DVPN client
Show answer & explanationAnswer & explanation
Correct answer: B. Firewall rules
Firewall rules explicitly define which network traffic is allowed or denied based on source, destination, port, and protocol, enabling precise control over a device's network access, aligning with the principle of least privilege.
Why the other options are wrong
- A. A DNS server resolves domain names to IP addresses, but doesn't enforce access policies.
- C. A DHCP server assigns IP addresses and configuration, but doesn't control network access.
- D. A VPN client creates a secure tunnel over an untrusted network, but doesn't inherently restrict internal network access.
Firewall Rules
Firewall rules are policies configured on a firewall that specify what network traffic is permitted or denied based on various criteria like source/destination IP, port, and protocol.
- Enforce network security policies.
- Can be stateless (packet filtering) or stateful (session-aware).
- Crucial for controlling inbound and outbound network access for devices and networks.
Memory trick: Firewall rules form a FENCE around your network access.