Courseiva
easyMultiple Choice

CAS-004 Practice Question: A network administrator is configuring a firewall…

A network administrator is configuring a firewall to allow only necessary traffic to a web server. The server should be accessible from the internet on port 443 and from a management subnet on port 22. Which firewall rule ensures least privilege?

⚠ Common exam trap

Candidates often choose an option that allows all traffic to the server (like Option C) thinking they can later block unwanted ports, but this violates the default-deny principle and is not considered least privilege in firewall design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow traffic from any to port 443, and from management subnet to port 22; deny all else

It explicitly allows only the required traffic (HTTPS on port 443 from any source, SSH on port 22 from the management subnet) and then denies all other traffic by default. This follows the principle of least privilege by ensuring no unintended services or sources are permitted, which is the core goal of firewall rule design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow traffic from management subnet to port 443 and any to port 22

    Why it's wrong here

    This rule grants management-subnet access to port 443 and opens port 22 to any source, violating least privilege on both counts. Management-subnet-to-port-22 paired with any-to-port-443 would be correct, since it matches the stated access requirements exactly.

  • ✗

    Allow traffic from any source to ports 443 and 22

    Why it's wrong here

    Opening port 22 to any source exposes SSH management to the entire internet rather than restricting it to the management subnet, violating least privilege. It is tempting because both required ports are permitted, and it would be correct if the management subnet were itself internet-routable and trusted.

  • ✗

    Allow all traffic to the server, then block specific ports

    Why it's wrong here

    A default-allow rule with later blocks grants every port and protocol except those explicitly denied, so the server is reachable on all unlisted services — the inverse of least privilege. It is tempting as a quick way to avoid lockout during configuration, and would suit a lab host where broad access is acceptable.

  • ✓

    Allow traffic from any to port 443, and from management subnet to port 22; deny all else

    Why this is correct

    This rule permits only the two required flows — HTTPS from anywhere and SSH restricted to the management subnet — then denies everything else. Scoping port 22 to the management subnet enforces least privilege, satisfying the constraint that the server be reachable only as specified.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.