SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security administrator is configuring a new firewall for a data center. The policy states that all outbound connections to the internet should be explicitly denied by default, and only specific, necessary services should be allowed. Which firewall rule configuration approach does this describe?
- AStateful Inspection
- BImplicit Allow
- CPacket Filtering
- DImplicit Deny
Show answer & explanationAnswer & explanation
Correct answer: D. Implicit Deny
Implicit Deny is a foundational security principle where any traffic not explicitly permitted by a firewall rule is automatically blocked. This 'deny all unless expressly permitted' approach is a best practice for strong security.
Why the other options are wrong
- A. Stateful Inspection is a firewall capability that tracks the state of active connections, not a policy approach for default traffic handling.
- B. Implicit Allow means anything not explicitly denied is permitted, which is a weak security posture.
- C. Packet Filtering is a basic firewall function that examines packet headers, but 'implicit deny' describes the policy applied to those packets.
Implicit Deny
Implicit Deny is a security principle, especially in firewall rules, where any access or traffic not explicitly permitted by a rule is automatically denied. It's a 'default deny' posture.
- Fundamental security best practice.
- 'Deny all, then allow exceptions.'
- Reduces attack surface by default.
- Opposite of Implicit Allow.
Memory trick: Firewall's golden rule: If it's not explicitly invited, it's not coming in.