FC0-U71 Security Practice Question
What is the primary purpose of a network firewall?
⚠ Common exam trap
FC0-U71 often tests the distinction between firewall functions and those of other security or networking devices, so candidates may confuse firewalls with antivirus, encryption tools, or wireless access points.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To block unauthorized network traffic based on rules
A network firewall's primary purpose is to control incoming and outgoing network traffic by comparing packets against a set of predefined security rules. It acts as a barrier between trusted internal networks and untrusted external networks (like the internet), allowing or denying traffic based on criteria such as IP addresses, ports, and protocols. This rule-based filtering is the core function that distinguishes a firewall from other security tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To prevent malware infections by scanning files
Why it's wrong here
Firewalls filter traffic by IP address, port and protocol; they do not scan file contents for malicious signatures, which is antivirus or endpoint protection software's role. It is tempting because both are perimeter security controls, but content scanning happens at the endpoint, not the packet-filtering layer.
- ✗
To encrypt data transmitted over the network
Why it's wrong here
Firewalls permit or deny packets based on rules; encryption is provided by TLS, IPsec or VPN protocols instead. It is tempting because firewalls often sit alongside VPN terminators, but confidentiality of transmitted data is a cryptographic function, not a packet-filtering one.
- ✓
To block unauthorized network traffic based on rules
Why this is correct
A firewall inspects packets against configured rule sets, permitting or denying traffic by source, destination, port and protocol. This directly fulfils the stem's requirement of blocking unauthorised network traffic, since each rule defines precisely which connections may pass the boundary between trusted and untrusted networks.
- ✗
To provide wireless network access
Why it's wrong here
Wireless access is delivered by wireless access points and controllers, not firewalls, which inspect and control traffic flows. It is tempting because firewalls are frequently deployed at network edges near wireless infrastructure, but they enforce security policy rather than broadcasting or authenticating radio connections.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.