GSEC Defensible Network Architecture Practice Question
A security administrator is configuring a screened subnet (DMZ) firewall rule set. The organization wants to allow external users to reach a public web server on TCP 443 while preventing the web server from initiating connections back into the internal network. Which rule set BEST enforces this requirement?
⚠ Common exam trap
The trap here is focusing only on the inbound permit and overlooking the need to both block outbound initiation to internal networks and allow established return traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permit any external IP to the web server on TCP 443; deny the web server to any internal IP on all ports; permit established return traffic from the web server to external clients.
A screened subnet firewall policy should permit only the specific public service, block the DMZ host from initiating connections into the internal network, and allow return traffic for established sessions. The rule set that permits external HTTPS, denies the web server to internal IPs, and permits established return traffic achieves this. Overly broad inbound rules or rules that allow inward initiation from the DMZ undermine the security boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permit any external IP to the web server on any port; deny the web server to any internal IP on all ports.
Why it's wrong here
Allowing any port from external sources exposes unnecessary services on the web server, such as management or database ports, increasing the attack surface. The requirement specifically calls for TCP 443, so permitting all ports is overly permissive. While the internal deny is correct, the inbound rule is too broad and violates the principle of least privilege for a public-facing host.
- ✓
Permit any external IP to the web server on TCP 443; deny the web server to any internal IP on all ports; permit established return traffic from the web server to external clients.
Why this is correct
This rule set allows inbound HTTPS to the public server and explicitly blocks the server from initiating connections to internal addresses. Permitting established return traffic lets responses to external clients flow back without opening new inbound sessions. It enforces the one-way trust boundary that a screened subnet is meant to provide while keeping the public service reachable.
- ✗
Deny all external IPs to the web server; permit the web server to any external IP on TCP 443.
Why it's wrong here
This rule set blocks the public from reaching the web server at all, defeating the purpose of hosting a public service. It also allows the web server to initiate outbound connections to arbitrary external addresses, which is the opposite of the intended control. The requirement is to permit inbound HTTPS and restrict outbound to internal networks, so this configuration is backwards.
- ✗
Permit any external IP to the web server on TCP 443; permit the web server to any internal IP on TCP 443 only.
Why it's wrong here
Allowing the web server to reach internal hosts on TCP 443 creates a direct path from the DMZ into the internal network. If the web server is compromised, an attacker could use that rule to pivot to internal web services. The requirement is to prevent the server from initiating connections inward, so this rule set directly violates the stated policy and is therefore incorrect.
Visual reference
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.