Courseiva

GSEC Defensible Network Architecture Practice Question

A security administrator is configuring a screened subnet (DMZ) firewall rule set. The organization wants to allow external users to reach a public web server on TCP 443 while preventing the web server from initiating connections back into the internal network. Which rule set BEST enforces this requirement?

⚠ Common exam trap

The trap here is focusing only on the inbound permit and overlooking the need to both block outbound initiation to internal networks and allow established return traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Permit any external IP to the web server on TCP 443; deny the web server to any internal IP on all ports; permit established return traffic from the web server to external clients.

A screened subnet firewall policy should permit only the specific public service, block the DMZ host from initiating connections into the internal network, and allow return traffic for established sessions. The rule set that permits external HTTPS, denies the web server to internal IPs, and permits established return traffic achieves this. Overly broad inbound rules or rules that allow inward initiation from the DMZ undermine the security boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Permit any external IP to the web server on any port; deny the web server to any internal IP on all ports.

    Why it's wrong here

    Allowing any port from external sources exposes unnecessary services on the web server, such as management or database ports, increasing the attack surface. The requirement specifically calls for TCP 443, so permitting all ports is overly permissive. While the internal deny is correct, the inbound rule is too broad and violates the principle of least privilege for a public-facing host.

  • ✓

    Permit any external IP to the web server on TCP 443; deny the web server to any internal IP on all ports; permit established return traffic from the web server to external clients.

    Why this is correct

    This rule set allows inbound HTTPS to the public server and explicitly blocks the server from initiating connections to internal addresses. Permitting established return traffic lets responses to external clients flow back without opening new inbound sessions. It enforces the one-way trust boundary that a screened subnet is meant to provide while keeping the public service reachable.

  • ✗

    Deny all external IPs to the web server; permit the web server to any external IP on TCP 443.

    Why it's wrong here

    This rule set blocks the public from reaching the web server at all, defeating the purpose of hosting a public service. It also allows the web server to initiate outbound connections to arbitrary external addresses, which is the opposite of the intended control. The requirement is to permit inbound HTTPS and restrict outbound to internal networks, so this configuration is backwards.

  • ✗

    Permit any external IP to the web server on TCP 443; permit the web server to any internal IP on TCP 443 only.

    Why it's wrong here

    Allowing the web server to reach internal hosts on TCP 443 creates a direct path from the DMZ into the internal network. If the web server is compromised, an attacker could use that rule to pivot to internal web services. The requirement is to prevent the server from initiating connections inward, so this rule set directly violates the stated policy and is therefore incorrect.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.