Courseiva
Network Security Devices →mediumMultiple Choice

GSEC Network Security Devices Practice Question

A security analyst is reviewing a network diagram and sees a device placed between the internet edge router and the internal firewall. The device is described as providing network address translation and stateful connection tracking but not deep application inspection. Which device type is most consistent with this description?

⚠ Common exam trap

The trap here is assuming that any device performing NAT and stateful tracking must be a next-generation firewall, when deep application inspection is explicitly absent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A stateful firewall that tracks TCP sessions and allows return traffic for established connections.

Stateful connection tracking and network address translation are core functions of a traditional stateful firewall, which maintains a session table and allows return traffic for established flows. The scenario explicitly excludes deep application inspection, ruling out a next-generation firewall. Stateless filtering lacks connection state, and a web proxy is application-specific rather than a general stateful gateway, so the stateful firewall is the correct device type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A stateless packet-filtering router that evaluates each packet independently against ACLs.

    Why it's wrong here

    Stateless packet filtering does not maintain connection state, so it cannot perform stateful connection tracking. It evaluates each packet in isolation against ACLs and often requires rules for both directions of a flow. The description explicitly includes stateful connection tracking and NAT, which go beyond stateless filtering. Therefore, a stateless packet-filtering router does not match the described capabilities.

  • ✓

    A stateful firewall that tracks TCP sessions and allows return traffic for established connections.

    Why this is correct

    A stateful firewall maintains a connection table and permits return traffic for sessions that were initiated according to policy. Many stateful firewalls also perform network address translation at the edge. The scenario describes stateful connection tracking and NAT but not deep application inspection, which is exactly the core behavior of a traditional stateful firewall. This device type fits the placement and described functions precisely.

  • ✗

    A next-generation firewall that performs full application-layer inspection and user identity mapping.

    Why it's wrong here

    A next-generation firewall does stateful tracking and NAT, but it also performs deep application inspection, application identification, and often user identity mapping. The scenario explicitly states that deep application inspection is not provided, so an NGFW exceeds the described capabilities. Although an NGFW could be placed in that position, the description points to a simpler stateful firewall rather than a full application-aware platform.

  • ✗

    A web proxy that terminates HTTP and HTTPS connections and enforces content policies.

    Why it's wrong here

    A web proxy operates at the application layer, terminates client connections, and enforces content or URL policies. It does not typically provide general-purpose stateful connection tracking for all protocols or network address translation for arbitrary traffic. The description mentions NAT and stateful connection tracking without application inspection, which is not the role of a web proxy. Therefore, this device type does not match the scenario.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.