GSEC Network Security Devices Practice Question
A financial services firm is selecting a web application firewall (WAF) to protect an internet-facing banking portal that uses TLS 1.3 exclusively. The security architect must ensure the WAF can inspect encrypted sessions and detect attacks that unfold across many requests from the same client. Which TWO capabilities are MOST relevant to these requirements? (Choose two.)
⚠ Common exam trap
The trap here is equating passive packet capture features, such as promiscuous mode, with the active decryption and session correlation a WAF needs to inspect modern TLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Terminating TLS at the WAF using a certificate and private key trusted by the portal's clients.
Inspecting TLS 1.3 forces the WAF to act as a TLS endpoint with the portal's certificate and key, because encrypted payloads are otherwise opaque. Detecting attacks spread across many requests requires persistent per-client session tracking and behavioral scoring, so those two capabilities together satisfy the architect's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configuring the WAF to operate only in detection mode with alerts sent to a SIEM.
Why it's wrong here
Detection-only mode produces alerts but does not block malicious requests, which is insufficient for protecting a live banking portal where active prevention is expected. Alerting to a SIEM is valuable for visibility, yet it does not address either stated requirement: inspecting TLS 1.3 content or correlating behavior across many requests from one client.
- ✗
Enabling promiscuous mode on the WAF's management interface.
Why it's wrong here
Promiscuous mode lets an interface capture frames not addressed to it, which is useful for passive sniffing but irrelevant to a WAF that must actively proxy and inspect HTTP traffic. It does not decrypt TLS 1.3, does not correlate requests, and enabling it on a management interface could actually expose sensitive administrative traffic on the segment.
- ✗
Disabling HTTP keep-alive so every request opens a fresh TCP connection.
Why it's wrong here
Forcing a new TCP connection per request would degrade portal performance and does not improve attack detection; correlation across requests is a function of application-layer session tracking, not connection reuse. In fact, breaking keep-alive can obscure client identity and complicate the very session state the WAF needs to detect multi-request attacks.
- ✓
Terminating TLS at the WAF using a certificate and private key trusted by the portal's clients.
Why this is correct
To inspect TLS 1.3 payloads, the WAF must be a TLS endpoint, which means presenting a certificate and possessing the corresponding private key so it can decrypt, examine, and re-encrypt sessions. Without this termination capability the WAF only sees ciphertext and cannot evaluate HTTP request content, making it useless against application-layer attacks on the portal.
- ✓
Maintaining per-client session state and scoring correlated requests over time.
Why this is correct
Attacks such as credential stuffing and slow application-layer abuse are distributed across many individual requests, so detecting them requires the WAF to correlate requests from the same client over a window of time. Stateless per-request matching alone would miss the pattern, making session-aware scoring essential for the banking portal's threat model.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.