GSEC Defensible Network Architecture Practice Question
A security engineer is segmenting a data center so that contractors who maintain HVAC systems cannot initiate connections into the server VLAN, but the internal monitoring platform must still reach the contractor subnet to poll building-management sensors. The chosen design uses a stateful firewall between the two zones with the contractor zone as the untrusted side. Which configuration best enforces the required traffic direction while preserving monitoring?
⚠ Common exam trap
The trap here is assuming that private IP addressing or a stateless ACL provides the same directional enforcement as a stateful firewall session table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the firewall so the monitoring platform initiates sessions into the contractor zone, allowing only established, return traffic back to the monitoring platform.
The requirement is directional control between zones, so a stateful firewall must see the trusted monitoring platform initiate the session and then allow only the return traffic for that established flow. Contractors are thereby unable to originate connections into the server VLAN, while polling of building-management sensors continues. Stateless ACLs and private addressing do not provide this session-aware, one-way enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place both zones behind a single perimeter firewall and permit all inter-zone traffic, relying on the contractor VLAN's private IP addressing to prevent reachability.
Why it's wrong here
RFC 1918 addressing provides no security boundary; routers and firewalls route between private subnets without any filtering. Permitting all inter-zone traffic lets contractors initiate connections directly into the server VLAN, defeating the segmentation goal. Private addressing is an addressing convention, not an access control, so it cannot substitute for a directional policy between the zones.
- ✓
Configure the firewall so the monitoring platform initiates sessions into the contractor zone, allowing only established, return traffic back to the monitoring platform.
Why this is correct
This enforces the required direction: the trusted monitoring platform originates the session, and the stateful firewall builds a session table entry so only return traffic for that flow is allowed back. Contractors cannot initiate inbound connections to the server VLAN, and monitoring still works because the firewall tracks the established session rather than trusting source addresses.
- ✗
Apply an ACL on the contractor zone's router interface that permits only the monitoring platform's IP to the sensor subnet and denies all other traffic in both directions.
Why it's wrong here
A stateless ACL on the contractor interface filters packets by address and port but does not track session state, so return traffic from the contractor subnet toward the monitoring platform would also need explicit permits and could be spoofed. It also permits the contractor zone to initiate toward the monitoring platform, which is exactly the connection direction that must be blocked.
- ✗
Configure a stateful firewall rule permitting the contractor subnet to the sensor subnet on the management ports, and add an implicit deny at the end of the rule base.
Why it's wrong here
This rule permits the wrong direction: it lets contractor systems originate connections toward the monitored zone, which is the traffic the design must forbid. The implicit deny at the end of the rule base is correct practice, but it does not fix the inverted source and destination. Monitoring would also fail because the platform's own outbound sessions would be denied.
Visual reference
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.