easyMultiple Select
CS0-003 Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for securing a network firewall configuration? (Choose two.)
⚠ Common exam trap
CompTIA often tests the distinction between operational practices (like log monitoring) and configuration best practices, leading candidates to mistakenly select continuous monitoring as a configuration control rather than a detection control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a default deny rule for inbound and outbound traffic
A default deny rule for inbound and outbound traffic ensures that only explicitly permitted traffic is allowed, which is the foundation of a secure firewall configuration. This approach aligns with the principle of least privilege and prevents unauthorized access or data exfiltration by blocking all traffic that is not specifically required. Without a default deny rule, any misconfiguration or unanticipated traffic could bypass security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a default deny rule for inbound and outbound traffic
Why this is correct
Implementing a default deny (or implicit deny) rule at the end of the firewall policy ensures that any traffic not explicitly permitted by a preceding rule is dropped. This foundational security posture prevents unauthorized inbound connections and restricts rogue outbound communications, significantly reducing the success of command-and-control (C2) channels.
- ✓
Apply least privilege access by restricting ports and IP addresses
Why this is correct
Restricting firewall rules to specific source/destination IP addresses and necessary destination ports enforces the principle of least privilege. By narrowing the scope of allowed network paths, organizations minimize the attack surface and prevent lateral movement in the event of a network compromise.
- ✗
Enable continuous monitoring of firewall logs
Why it's wrong here
While continuous monitoring of firewall logs is critical for threat detection and incident response, it is an operational and administrative practice rather than a direct firewall hardening configuration. Hardening focuses on active traffic filtering rules and device access controls rather than passive log analysis.
- ✗
Allow all traffic by default and block specific threats
Why it's wrong here
This approach, known as default allow, relies on reactive blacklisting which is highly insecure because it permits all unknown or zero-day threats by default. Modern network security mandates a default deny posture, where only known, validated traffic is permitted, and everything else is blocked.
- ✗
Use default vendor passwords for initial access
Why it's wrong here
Utilizing default vendor credentials, even temporarily, exposes the firewall to immediate compromise via automated scanning tools and brute-force scripts. Hardening guidelines dictate that default passwords must be changed to strong, unique credentials before the device is connected to any network.
Visual reference
Go deeper
Related to this question
Learn chapter
Security SLAs and SLOs
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.