Courseiva
Question 198 of 464
Network SecurityhardMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A security administrator is configuring a firewall to allow remote employees to access the company's internal web server (port 443) from the internet. The web server has an internal IP address of 10.0.0.5. The firewall has a public IP of 203.0.113.10. Which type of firewall rule should be created?

⚠ Common exam trap

Watch out — candidates often confuse a simple 'allow' rule with the necessary NAT translation, failing to realize that without DNAT, the firewall has no way to forward the packet to the private IP address of the internal server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A) Port forwarding (DNAT) rule

A port forwarding (DNAT) rule is required because the web server uses a private RFC 1918 IP address (10.0.0.5), which is not routable on the public internet. The firewall must translate the destination IP from its public address (203.0.113.10) to the internal server's private address, allowing inbound traffic on port 443 to reach the correct internal host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A) Port forwarding (DNAT) rule

    Why this is correct

    Port forwarding, also known as Destination Network Address Translation (DNAT), is the correct solution because it modifies the destination IP address and port of incoming network packets. When an external client sends traffic to the firewall's public IP address on a specific port, the DNAT rule translates this public address and port to the internal private IP address and port of the target server. This allows the remote employees' traffic, destined for the public IP, to be correctly routed to the internal server within the private network, making the service externally accessible.

  • B) Allow rule with source any, destination 10.0.0.5, port 443

    Why it's wrong here

    An allow rule with a destination of 10.0.0.5 would permit traffic *if* the packet's destination IP was already 10.0.0.5. However, incoming traffic from the internet is addressed to the firewall's public IP (e.g., 203.0.113.10), not the internal private IP. Without an accompanying address translation mechanism like DNAT, the firewall would simply drop or reject packets whose destination IP does not match an interface or a routing entry, as the internal server's private IP is not directly reachable from the internet.

  • C) Access control list on the internal interface

    Why it's wrong here

    An Access Control List (ACL) applied to an internal interface primarily governs traffic flow *within* the private network or traffic attempting to *exit* the private network through that interface. While an ACL can filter traffic based on source, destination, and port, it does not perform the crucial function of translating public IP addresses to private ones for incoming external connections. Therefore, an internal ACL cannot enable remote employees to initiate connections to an internal server from the internet.

    When this WOULD be correct

    This option would be correct if the question asked about controlling outbound traffic from the internal network to the internet, such as restricting which internal users can access external web servers on port 443.

  • D) VPN rule to require remote access VPN

    Why it's wrong here

    A VPN rule would mandate that remote employees establish a Virtual Private Network tunnel to the corporate network before accessing any internal resources. While VPNs provide secure remote access, the question implies a direct internet-based access method for a service, not a requirement for users to connect via a VPN client. Implementing a VPN rule would prevent direct public access to the service and instead force all remote connections through a secure, encrypted tunnel, which is not the stated goal.

    When this WOULD be correct

    A VPN rule would be correct if the scenario required secure, encrypted access to the entire internal network or multiple services, and the organization policy mandated that all remote access must go through a VPN for security compliance.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

A) Port forwarding (DNAT) ruleCorrect answer

Why this is correct

Port forwarding, also known as Destination Network Address Translation (DNAT), is the correct solution because it modifies the destination IP address and port of incoming network packets. When an external client sends traffic to the firewall's public IP address on a specific port, the DNAT rule translates this public address and port to the internal private IP address and port of the target server. This allows the remote employees' traffic, destined for the public IP, to be correctly routed to the internal server within the private network, making the service externally accessible.

C) Access control list on the internal interfaceWrong answer — click to see why

Why this is wrong here

An access control list on the internal interface would only control traffic already inside the network, not allow inbound connections from the internet to the internal web server. The firewall must translate the public IP to the private IP, which DNAT does.

★ When this WOULD be the correct answer

This option would be correct if the question asked about controlling outbound traffic from the internal network to the internet, such as restricting which internal users can access external web servers on port 443.

Why candidates choose this

Candidates may think ACLs are the standard way to permit traffic, but they overlook that ACLs alone cannot handle the address translation needed for inbound traffic from the internet to a private IP.

D) VPN rule to require remote access VPNWrong answer — click to see why

Why this is wrong here

The question asks for a firewall rule to allow remote employees to access the internal web server from the internet. A VPN rule is not required for simple port forwarding; it would be an unnecessary complication and not the direct solution for allowing access via port 443.

★ When this WOULD be the correct answer

A VPN rule would be correct if the scenario required secure, encrypted access to the entire internal network or multiple services, and the organization policy mandated that all remote access must go through a VPN for security compliance.

Why candidates choose this

Candidates may think that remote access always requires a VPN for security, overlooking that a simple DNAT rule with proper firewall policies can securely expose a single service like HTTPS.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.