CompTIA Tech+ (FC0-U71)SecurityMedium

A network administrator is configuring a new firewall for a company. The company policy states that all network traffic not explicitly allowed should be blocked by default. Which firewall rule concept is being applied here?

  1. ADemilitarized Zone (DMZ)
  2. BStateful Inspection
  3. CPort Forwarding
  4. DImplicit Deny
Show answer & explanation

Correct answer: D. Implicit Deny

The 'Implicit Deny' principle states that if a firewall rule does not explicitly allow traffic, that traffic is automatically denied. This ensures that only authorized communication can pass through, making it a fundamental security best practice.

Why the other options are wrong

  • A. A DMZ is a network segment for public-facing servers, not a rule concept for blocking unallowed traffic.
  • B. Stateful inspection tracks connection states but doesn't define the default action for unallowed traffic.
  • C. Port forwarding redirects traffic from one port to another, not a general blocking principle.

Implicit Deny

A security principle in firewalls and access control lists (ACLs) that states any traffic or access not explicitly permitted is automatically denied.

  • Fundamental security best practice.
  • Ensures only necessary traffic is allowed.
  • Often the last rule in a firewall's rule set.

Memory trick: If it's not explicitly OPEN, it's IMPLICITLY DENIED.

More Security questions