CompTIA Tech+ (FC0-U71)SecurityMedium

A network administrator is configuring a new firewall to restrict outbound internet access for employees. The administrator wants to ensure that if a specific rule is not explicitly defined to allow traffic, that traffic is automatically blocked. Which security principle is the administrator implementing?

  1. ADefense in Depth
  2. BSeparation of Duties
  3. CImplicit Deny
  4. DLeast Privilege
Show answer & explanation

Correct answer: C. Implicit Deny

Implicit deny is a firewall rule that states that unless traffic is explicitly allowed by a rule, it is automatically denied. This ensures that only necessary and approved network communications are permitted, enhancing security.

Why the other options are wrong

  • A. Defense in depth involves multiple layers of security, which is a broader concept than a single firewall rule.
  • B. Separation of duties divides tasks among different individuals to prevent fraud or error, not directly related to firewall traffic rules.
  • D. Least privilege applies to user permissions, granting only the minimum necessary to perform their job, not specifically firewall traffic rules.

Implicit Deny

A security principle, especially in firewalls, where any access or traffic not explicitly allowed by a rule is automatically blocked.

  • Default action is to deny everything.
  • Requires explicit rules for permitted traffic.
  • Enhances security by limiting potential attack surfaces.

Memory trick: Deny all, unless explicitly allowed.

More Security questions