Courseiva
easyMultiple Select

CS0-003 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for securing a network firewall configuration? (Choose two.)

⚠ Common exam trap

CompTIA often tests the distinction between operational practices (like log monitoring) and configuration best practices, leading candidates to mistakenly select continuous monitoring as a configuration control rather than a detection control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a default deny rule for inbound and outbound traffic

A default deny rule for inbound and outbound traffic ensures that only explicitly permitted traffic is allowed, which is the foundation of a secure firewall configuration. This approach aligns with the principle of least privilege and prevents unauthorized access or data exfiltration by blocking all traffic that is not specifically required. Without a default deny rule, any misconfiguration or unanticipated traffic could bypass security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a default deny rule for inbound and outbound traffic

    Why this is correct

    Implementing a default deny (or implicit deny) rule at the end of the firewall policy ensures that any traffic not explicitly permitted by a preceding rule is dropped. This foundational security posture prevents unauthorized inbound connections and restricts rogue outbound communications, significantly reducing the success of command-and-control (C2) channels.

  • ✓

    Apply least privilege access by restricting ports and IP addresses

    Why this is correct

    Restricting firewall rules to specific source/destination IP addresses and necessary destination ports enforces the principle of least privilege. By narrowing the scope of allowed network paths, organizations minimize the attack surface and prevent lateral movement in the event of a network compromise.

  • ✗

    Enable continuous monitoring of firewall logs

    Why it's wrong here

    While continuous monitoring of firewall logs is critical for threat detection and incident response, it is an operational and administrative practice rather than a direct firewall hardening configuration. Hardening focuses on active traffic filtering rules and device access controls rather than passive log analysis.

  • ✗

    Allow all traffic by default and block specific threats

    Why it's wrong here

    This approach, known as default allow, relies on reactive blacklisting which is highly insecure because it permits all unknown or zero-day threats by default. Modern network security mandates a default deny posture, where only known, validated traffic is permitted, and everything else is blocked.

  • ✗

    Use default vendor passwords for initial access

    Why it's wrong here

    Utilizing default vendor credentials, even temporarily, exposes the firewall to immediate compromise via automated scanning tools and brute-force scripts. Hardening guidelines dictate that default passwords must be changed to strong, unique credentials before the device is connected to any network.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.