CompTIA Network+ (N10-009)Network SecurityMedium
A firewall administrator needs a device that automatically allows return traffic for an established outbound connection without requiring a separate explicit rule for the reply packets. Which firewall type provides this behavior?
- AStateless packet-filtering firewall
- BIntrusion detection system
- CStateful firewall
- DWeb application firewall
Show answer & explanationAnswer & explanation
Correct answer: C. Stateful firewall
A stateful firewall maintains a connection state table, tracking the state of active sessions so it can automatically permit legitimate return traffic that belongs to an already-approved session. Stateless firewalls evaluate each packet independently, requiring separate rules for both directions.
Why the other options are wrong
- A. Stateless firewalls inspect each packet in isolation and need explicit rules for both directions.
- B. An IDS detects and alerts on suspicious traffic but does not enforce blocking or track sessions for filtering.
- D. A WAF inspects HTTP-layer application traffic, not general session state.
Stateful Firewall
A firewall that tracks the state of active network connections in a state table and automatically permits related return traffic.
- Maintains a connection state table
- Reduces rule complexity vs. stateless filtering
- Common in modern NGFWs
Memory trick: Stateful firewalls remember the conversation; stateless ones forget after every sentence.