Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A company is implementing a new firewall and needs to ensure that all internal hosts can access external web resources, but external hosts cannot initiate connections into the internal network unless explicitly allowed for specific services. Which firewall policy model best describes this requirement?

  1. AProxy Firewall
  2. BPacket Filtering
  3. CApplication Layer Gateway
  4. DStateful Inspection
Show answer & explanation

Correct answer: D. Stateful Inspection

Stateful inspection firewalls track the state of active connections. They automatically allow return traffic for connections initiated from the inside, while blocking unsolicited external connections, which perfectly matches the described requirement.

Why the other options are wrong

  • A. Proxy firewalls act as intermediaries, which provides strong security but is a more complex solution than simply managing connection states for basic web access.
  • B. Packet filtering inspects individual packets without regard to connection state, making it less effective for this requirement and requiring explicit rules for return traffic.
  • C. Application Layer Gateways (ALGs) handle protocol-specific commands and data, but the core requirement is about connection state, not application-level parsing.

Stateful Inspection Firewall

A stateful inspection firewall monitors the state of active connections, making decisions based on the connection's context and allowing return traffic for legitimate outbound sessions.

  • Tracks connection state (e.g., SYN, SYN-ACK, ACK).
  • Allows return traffic for outbound connections automatically.
  • Blocks unsolicited inbound connections.
  • Operates at the network and transport layers.

Memory trick: Stateful remembers the conversation, like a good bouncer.

More Network Security questions