SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium

A network administrator is configuring a new firewall rule to allow specific internal servers to initiate outbound connections to a web service hosted on the internet on a non-standard port, 8443. Which of the following firewall rules would correctly permit this communication while adhering to the principle of least privilege?

  1. APermit ANY Source, Destination [Web Service IP], Port 8443, Protocol TCP
  2. BPermit Source [Internal Servers IP Range], Destination ANY, Port 8443, Protocol TCP
  3. CPermit ANY Source, ANY Destination, Port ANY, Protocol ANY
  4. DPermit Source [Internal Servers IP Range], Destination [Web Service IP], Port 8443, Protocol TCP
Show answer & explanation

Correct answer: D. Permit Source [Internal Servers IP Range], Destination [Web Service IP], Port 8443, Protocol TCP

To adhere to the principle of least privilege, the firewall rule should be as specific as possible. This means specifying the exact source (internal servers), the exact destination (web service IP), the correct port (8443), and the correct protocol (TCP).

Why the other options are wrong

  • A. This rule is too broad on the source, allowing any internal host to connect to the web service, which violates least privilege.
  • B. This rule is too broad on the destination, allowing connections to any destination on port 8443, which violates least privilege.
  • C. This rule is overly permissive and violates the principle of least privilege by allowing all traffic.

Firewall Rule Least Privilege

Configuring firewall rules to grant only the minimum necessary access required for functionality, specifying exact sources, destinations, ports, and protocols.

  • Restricts access to only what is needed.
  • Minimizes the attack surface.
  • Requires specific source, destination, port, and protocol definitions.

Memory trick: Firewall Rules Must Be Precise.

More Network and Communications Security questions