Courseiva
Security →mediumMultiple Select

CV0-004 Security Practice Question

A cloud administrator is configuring network ACLs (NACLs) for a VPC subnet. The subnet hosts a web server that must accept HTTP (port 80) and HTTPS (port 443) from the internet, and the server needs to respond to clients. Which TWO rules are required?

⚠ Common exam trap

CV0-004 often tests the stateless nature of NACLs — candidates incorrectly assume that allowing inbound 80/443 automatically permits return traffic, confusing NACLs with stateful security groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Outbound rule: allow TCP ports 1024-65535 to 0.0.0.0/0

Option E is correct because the web server must accept inbound HTTP and HTTPS traffic from the internet, so the NACL needs an inbound rule permitting TCP ports 80 and 443 from 0.0.0.0/0. Option D is correct because NACLs are stateless, meaning return traffic is not automatically allowed; the server's responses to clients use ephemeral source ports in the 1024-65535 range, so an outbound rule allowing TCP ports 1024-65535 to 0.0.0.0/0 is required for the responses to reach clients. Option A is not required because ICMP is not needed for HTTP/HTTPS web service and is unrelated to the stated requirement. Option B is wrong because outbound traffic from the server does not originate from ports 80/443; those are the listening ports, while responses use ephemeral ports. Option C is wrong because inbound client requests target destination ports 80/443, not the ephemeral range, so allowing 1024-65535 inbound would not satisfy the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inbound rule: allow all ICMP from 0.0.0.0/0

    Why it's wrong here

    ICMP permits ping and traceroute diagnostics, not HTTP or HTTPS traffic, so it fails to admit the required ports 80 and 443. It is tempting because ICMP rules are commonly added for reachability testing, and would be correct where troubleshooting connectivity to the subnet is the goal.

  • ✗

    Outbound rule: allow TCP port 80 and 443 to 0.0.0.0/0

    Why it's wrong here

    NACLs are stateless, so return traffic from the web server to clients uses ephemeral source ports (typically 1024–65535), not 80 or 443. Allowing outbound 80/443 is tempting by symmetry with the inbound rules, but it permits the server to initiate web requests rather than answer them.

  • ✗

    Inbound rule: allow TCP ports 1024-65535 from 0.0.0.0/0

    Why it's wrong here

    NACLs are stateless, so return traffic from the server to clients uses ephemeral source ports; this rule opens those ports inbound rather than outbound, admitting unsolicited connections while still blocking replies. It would be correct as an outbound rule permitting responses to internet clients.

  • ✓

    Outbound rule: allow TCP ports 1024-65535 to 0.0.0.0/0

    Why this is correct

    Responses from the web server leave via ephemeral source ports 1024-65535, so the NACL needs an outbound rule permitting that range to 0.0.0.0/0. Without it, return traffic to internet clients is blocked and connections fail.

  • ✓

    Inbound rule: allow TCP port 80 and 443 from 0.0.0.0/0

    Why this is correct

    NACLs are stateless, so return traffic is not automatically permitted. This inbound rule opens TCP ports 80 and 443 to any source, satisfying the requirement that the web server accept HTTP and HTTPS from the internet; a matching outbound rule for ephemeral ports is also needed.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.