Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A security engineer is configuring a network security group (NSG) in Azure to allow inbound HTTPS traffic to a web server. The engineer creates an inbound rule allowing TCP port 443 from the Internet. What must be done to ensure the web server can respond to clients?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No additional rule is needed because the NSG is stateful.

NSGs are stateful; allowing inbound traffic automatically allows the corresponding outbound response traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an outbound rule allowing all traffic to the Internet.

    Why it's wrong here

    Stateful NSGs already allow the return traffic for the established inbound session, so permitting all outbound traffic adds unnecessary exposure. It is tempting as a catch-all fix, and such a broad rule would be correct only where many distinct outbound destinations must be reached.

  • ✗

    Create an inbound rule allowing TCP port 443 from the web server.

    Why it's wrong here

    An inbound rule cannot originate from the web server to itself; responses leave as outbound traffic, which stateful NSGs already permit. It is tempting because it mirrors the existing rule, and such a rule would be correct only for traffic genuinely arriving from that server's address.

  • ✗

    Create an outbound rule allowing TCP port 443 to the Internet.

    Why it's wrong here

    NSGs are stateful, so the permitted inbound TCP 443 session automatically allows the return traffic; no outbound rule is needed. It is tempting because firewalls are often assumed to filter both directions, and an explicit outbound rule would be correct for stateless packet filtering.

  • ✓

    No additional rule is needed because the NSG is stateful.

    Why this is correct

    Network security groups are stateful, so return traffic for an allowed inbound connection is automatically permitted regardless of outbound rules. Because the inbound TCP 443 rule already establishes the flow, replies from the web server reach clients without any additional outbound rule.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.