Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A company wants to protect its network from unauthorized external access. Which of the following devices should be configured to filter traffic based on port and protocol?

⚠ Common exam trap

The trap is confusing host-based firewalls with network firewalls — candidates see 'firewall' in both options and pick the host-based one, forgetting the question asks about protecting the entire network from external access, which requires a perimeter device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network firewall

A network firewall is specifically designed to inspect and filter traffic traversing the network perimeter based on rules that match port numbers, protocols (TCP/UDP/ICMP), and source/destination IP addresses. It sits between the internal network and external networks, making it the correct device to block unauthorized external access at the network boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network firewall

    Why this is correct

    A network firewall inspects inbound and outbound packets, applying rules that permit or deny traffic by TCP/UDP port and protocol. This directly satisfies the requirement to filter unauthorised external access at the network perimeter, unlike switches or access points that forward traffic without such policy enforcement.

  • ✗

    Host-based firewall

    Why it's wrong here

    A host-based firewall filters traffic only for the single endpoint it is installed on, not the network perimeter, so it cannot block external access to the whole company network. It is tempting because it does filter by port and protocol, and would be correct for protecting one individual workstation.

  • ✗

    VPN concentrator

    Why it's wrong here

    A VPN concentrator terminates encrypted tunnels for remote users; it does not inspect and filter inbound traffic by port and protocol at the network edge. It is tempting because it secures external connectivity, and would be correct when many remote workers need encrypted access to internal resources.

  • ✗

    Antivirus software

    Why it's wrong here

    Antivirus software scans files and processes on endpoints for malicious code; it does not filter network traffic by port and protocol at the perimeter. It is tempting because it defends against external threats, and would be correct for detecting malware already present on a user's machine.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.