Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A security team is implementing a network segmentation strategy to isolate critical servers from the general user network. They have deployed a firewall between these segments. To further enhance security, they want to limit the protocols allowed to communicate with the critical servers to only the absolute necessities. This approach aligns with which security best practice?

  1. AMaximizing Attack Surface
  2. BImplicit Allow
  3. CDefault Deny
  4. DPromiscuous Mode
Show answer & explanation

Correct answer: C. Default Deny

The default deny (or 'least privilege' in a firewall context) principle dictates that all traffic is blocked unless explicitly permitted. This ensures that only necessary protocols can access critical servers, minimizing the attack surface.

Why the other options are wrong

  • A. Maximizing attack surface would involve allowing excessive access, which is the opposite of the goal.
  • B. Implicit allow would mean all traffic is allowed unless explicitly blocked, which is a less secure approach.
  • D. Promiscuous mode is a network interface card (NIC) setting that allows it to receive all network traffic, not a firewall policy.

Default Deny

Default deny (or implicit deny) is a security principle stating that all access to a resource is forbidden unless explicitly granted. It is commonly implemented in firewalls, access control lists, and user permissions.

  • All traffic is blocked unless an explicit rule permits it.
  • Minimizes the attack surface.
  • Ensures only necessary services are exposed.

Memory trick: Default Deny: The 'default' answer is 'NO' unless I say 'YES'.

More Network Security questions