CompTIA Network+ (N10-009)Network SecurityMedium

A firewall administrator needs a device that automatically allows return traffic for an established outbound connection without requiring a separate explicit rule for the reply packets. Which firewall type provides this behavior?

  1. AStateless packet-filtering firewall
  2. BIntrusion detection system
  3. CStateful firewall
  4. DWeb application firewall
Show answer & explanation

Correct answer: C. Stateful firewall

A stateful firewall maintains a connection state table, tracking the state of active sessions so it can automatically permit legitimate return traffic that belongs to an already-approved session. Stateless firewalls evaluate each packet independently, requiring separate rules for both directions.

Why the other options are wrong

  • A. Stateless firewalls inspect each packet in isolation and need explicit rules for both directions.
  • B. An IDS detects and alerts on suspicious traffic but does not enforce blocking or track sessions for filtering.
  • D. A WAF inspects HTTP-layer application traffic, not general session state.

Stateful Firewall

A firewall that tracks the state of active network connections in a state table and automatically permits related return traffic.

  • Maintains a connection state table
  • Reduces rule complexity vs. stateless filtering
  • Common in modern NGFWs

Memory trick: Stateful firewalls remember the conversation; stateless ones forget after every sentence.

More Network Security questions