Courseiva
hardMultiple Choice

CAS-004 Practice Question: A security analyst observes that SSH connections…

Network Topology
0 0 ACCEPT alllo * 0.0.0.0/0100 540 DROP tcp50 3000 ACCEPT tcp20 1200 ACCEPT tcpRefer to the exhibit.```

A security analyst observes that SSH connections to the server are failing, but HTTP and HTTPS traffic works. Based on the exhibit, what is the most likely cause?

⚠ Common exam trap

Watch out — candidates often assume SSH is failing due to a service misconfiguration (Option D) or an overly restrictive allow rule (Option C), but the exhibit clearly shows a specific drop rule for port 22, which is the definitive cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SSH service is being blocked by a firewall rule that drops TCP port 22 traffic.

The exhibit shows a firewall rule that explicitly drops TCP port 22 traffic, which is the default port for SSH. Since HTTP (port 80) and HTTPS (port 443) are unaffected, the issue is isolated to SSH. This rule is the most direct cause of the connection failures, as it blocks all SSH traffic regardless of source or destination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HTTPS rule is overriding the SSH rule.

    Why it's wrong here

    Security group rules are evaluated independently and additively; a permit for HTTPS on port 443 cannot override or negate a separate SSH rule on port 22. It is tempting because rule ordering matters in some firewall products, and that would be correct for a stateful appliance using first-match top-down evaluation.

  • ✓

    The SSH service is being blocked by a firewall rule that drops TCP port 22 traffic.

    Why this is correct

    SSH uses TCP port 22, whereas HTTP and HTTPS use ports 80 and 443. A firewall rule dropping TCP 22 blocks only SSH while leaving web traffic unaffected, matching the stem's symptom of failing SSH with working HTTP and HTTPS.

  • ✗

    The SSH service is only allowed from the 10.0.0.0/8 subnet.

    Why it's wrong here

    A subnet restriction would still permit SSH from within 10.0.0.0/8, yet the exhibit shows the connection failing regardless of source, so source-scoping cannot explain it. It is tempting because security groups and ACLs commonly restrict management ports by CIDR, and that would be correct if only external SSH attempts failed.

  • ✗

    The SSH service is misconfigured and not listening on the correct interface.

    Why it's wrong here

    A service not listening on the correct interface would also break HTTP and HTTPS if bound to the same interface, so it fails to explain why only SSH fails. It is tempting because misbound listeners do cause selective failures, and it would be correct if the exhibit showed SSH bound to loopback only.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.