Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityHard
A security team is implementing a host-based firewall policy for all corporate workstations. Which of the following rules, if incorrectly configured, would pose the GREATEST risk of inadvertently allowing malicious outbound connections while still permitting legitimate user activity?
- ADeny all outbound traffic to known malicious IP addresses.
- BAllow all inbound traffic on port 22 (SSH).
- CDeny all inbound traffic from external networks.
- DAllow all outbound traffic on port 80 (HTTP) to any destination.
Show answer & explanationAnswer & explanation
Correct answer: D. Allow all outbound traffic on port 80 (HTTP) to any destination.
Allowing all outbound HTTP traffic (port 80) to any destination is highly permissive. While it enables legitimate web browsing, it also allows malware to easily communicate with command-and-control (C2) servers over a commonly open port, potentially bypassing other network-level protections that might filter non-standard ports.
Why the other options are wrong
- A. Denying outbound to known malicious IPs is a good security practice and reduces risk, not increases it.
- B. Allowing inbound SSH (port 22) is risky for inbound connections, but the question asks about outbound malicious connections.
- C. Denying all inbound from external networks is a strong protective measure against external threats and does not relate to outbound malicious connections.
Host-based Firewall Rules
Rules configured on an individual computer (host) to control inbound and outbound network traffic, enhancing endpoint security.
- Operates at the endpoint level.
- Can be configured to allow or deny traffic based on ports, protocols, and IP addresses.
- Incorrect configuration can create vulnerabilities.
Memory trick: Every open door is an opportunity for friends or foes.