SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security administrator is configuring a new firewall for a data center. The policy states that only specific services (HTTP, HTTPS, SSH) are allowed to external networks, and all other traffic is implicitly denied. Which of the following concepts is being applied here?
- ALeast privilege
- BImplicit deny
- CSeparation of duties
- DDefense in depth
Show answer & explanationAnswer & explanation
Correct answer: B. Implicit deny
Implicit deny is a fundamental firewall principle where any traffic not explicitly permitted by a rule is automatically blocked. This ensures that only authorized services can pass through.
Why the other options are wrong
- A. Least privilege applies to user permissions, not network traffic rules.
- C. Separation of duties distributes tasks to prevent single points of failure or malicious acts.
- D. Defense in depth involves multiple layers of security controls, not a single firewall rule concept.
Implicit Deny
Implicit deny is a firewall rule that states if a packet does not match any 'allow' rules, it will be automatically denied. This provides a secure default posture.
- Last rule in a firewall's access control list (ACL).
- Enhances security by blocking unapproved traffic.
- Often represented as 'deny any any' at the end of a rule set.
Memory trick: If it's not on the guest list, it's not coming in the club.