Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A network engineer is configuring a firewall for a new corporate network segment. The policy dictates that all outbound web traffic (HTTP and HTTPS) from internal users should be allowed, but all other outbound traffic, unless explicitly permitted, should be blocked by default. Which firewall rule concept is the engineer applying for the default blocking of unpermitted traffic?

  1. AExplicit deny
  2. BImplicit deny
  3. CImplicit allow
  4. DStateful inspection
Show answer & explanation

Correct answer: B. Implicit deny

Implicit deny is a fundamental firewall principle where any traffic that is not explicitly permitted by a rule is automatically blocked. The scenario states that 'all other outbound traffic, unless explicitly permitted, should be blocked by default,' which directly describes the implicit deny rule.

Why the other options are wrong

  • A. Explicit deny is a specific rule to block certain traffic, but 'implicit deny' is the default behavior when no rule matches.
  • C. Implicit allow means anything not explicitly denied is allowed, which is the opposite of the scenario.
  • D. Stateful inspection is a firewall feature that tracks the state of active connections, not a rule concept for default blocking.

Implicit Deny

A security principle, especially in firewalls, where any access or action not explicitly permitted is automatically denied.

  • Provides a secure default posture.
  • Often the last rule in a firewall's access control list (ACL).
  • Ensures only intended traffic is allowed.

Memory trick: Firewall rules are like bouncers at a club: if you're not on the list, you're not getting in.

More Security Fundamentals questions