GSEC Network Security Devices Practice Question
A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?
⚠ Common exam trap
Many exam-takers confuse stateful session tracking with other firewall features like DPI or NAT, or assuming that an ACL must be added to allow return traffic, when the real issue is that stateful inspection is not functioning correctly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stateful inspection with session tracking
Stateful inspection with session tracking allows the firewall to dynamically permit return traffic for outbound connections by maintaining a session table. Without it, return packets are treated as new inbound traffic and may be blocked by default. The administrator should verify that stateful inspection is enabled and that the session table is not exhausted, which can cause drops.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Stateful inspection with session tracking
Why this is correct
Stateful inspection maintains a session table that tracks the state of each connection. When an outbound connection is initiated, the firewall creates an entry, and return traffic matching that session is automatically allowed. If session tracking is disabled or the table is full, return packets may be dropped. This feature is essential for allowing return traffic without explicit inbound rules.
- ✗
Access control lists (ACLs) applied to the inbound interface
Why it's wrong here
ACLs are static rules that filter traffic based on IP addresses, ports, and protocols. They do not dynamically allow return traffic for outbound sessions. If an ACL is blocking return traffic, it would need an explicit rule to permit it, but that is not a scalable or secure solution for stateful firewalls. The problem is with session tracking, not ACL configuration.
- ✗
Deep packet inspection (DPI) with application signatures
Why it's wrong here
DPI examines packet payloads for application-layer threats but does not inherently manage session state for return traffic. While DPI can identify applications, it does not create dynamic allow rules for return packets. The issue described is about session tracking, not application identification. Enabling DPI would not resolve the dropped return traffic unless stateful inspection is also functioning.
- ✗
Network address translation (NAT) with port forwarding
Why it's wrong here
NAT with port forwarding is used to allow inbound connections to internal servers, not to manage return traffic for outbound sessions. While NAT can translate addresses, it does not create session state. The firewall's stateful engine should handle return traffic automatically if session tracking is enabled. Port forwarding would not address the described issue.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.