Courseiva
easyMultiple Choice

200-901 Practice Question: Needs to allow HTTPS traffic from the internet to…

A network engineer needs to allow HTTPS traffic from the internet to an internal web server. Which type of firewall rule should be applied on the perimeter firewall?

⚠ Common exam trap

The trap is confusing inbound and outbound ACLs; candidates may think an outbound ACL on the inside interface is needed to allow return traffic, but the initial request from the internet must be permitted by an inbound ACL on the outside interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inbound ACL on the outside interface

To allow HTTPS traffic from the internet to an internal web server, you need an inbound ACL on the outside interface of the perimeter firewall. This ACL will permit TCP port 443 (HTTPS) from any external source to the public IP address of the web server (often via static NAT). Inbound ACLs filter traffic entering the firewall from the untrusted network, which is exactly where the internet traffic arrives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Routing protocol configuration

    Why it's wrong here

    Routing protocols exchange reachability information between layer-3 devices; they do not filter or permit traffic by port and direction. The requirement is a firewall rule permitting TCP 443 inbound to the web server. Routing configuration would be correct when advertising internal subnets to a neighbouring router.

  • ✗

    Outbound ACL on the inside interface

    Why it's wrong here

    An outbound ACL on the inside interface filters traffic leaving the internal network, so it cannot permit inbound HTTPS sessions arriving from the internet. Inbound rules on the outside interface govern that direction. Outbound ACLs suit controlling internal users' egress to external destinations.

  • ✓

    Inbound ACL on the outside interface

    Why this is correct

    An inbound ACL on the outside interface filters traffic arriving from the internet, permitting TCP 443 to the internal web server's translated address while denying other inbound flows. This satisfies the requirement to expose HTTPS only, applied at the perimeter where untrusted traffic first enters.

  • ✗

    Static NAT configuration

    Why it's wrong here

    Static NAT maps a public address to the internal server's private address but performs no port or direction filtering, so it alone does not permit HTTPS. A firewall rule allowing TCP 443 inbound is still required. Static NAT suits publishing a server once the accompanying permit rule exists.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.