ISC2 CC Network Security Practice Question
A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?
⚠ Common exam trap
The trap here is assuming that any firewall or IPS automatically defeats fragmentation evasion, when reassembly before rule evaluation is a specific capability that must be confirmed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A packet-filtering firewall that reassembles fragments before applying rules.
The requirement is deterministic network-layer access control on a specific port combined with protection against fragmentation evasion. A packet-filtering firewall that reassembles fragments before applying rules does exactly that, whereas application gateways, stateful inspection, and intrusion prevention systems address different concerns and do not guarantee both the source restriction and the anti-fragmentation behavior in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A stateful inspection firewall that tracks established TCP sessions.
Why it's wrong here
Stateful inspection tracks connection state so return traffic is permitted without an explicit rule, which improves accuracy for established sessions, but it does not by itself guarantee that fragmented packets are reassembled and checked against the source-subnet rule. The scenario specifically calls out fragmentation evasion, so a control focused on session state does not fully address the requirement.
- ✗
A network intrusion prevention system tuned to the trading protocol.
Why it's wrong here
A network intrusion prevention system detects and blocks known malicious patterns in traffic, but it is not the primary mechanism for enforcing source-subnet allow lists on a specific TCP port. It also may not reliably reassemble fragments before detection, so it does not provide the deterministic access control and anti-evasion guarantee the firm requires.
- ✓
A packet-filtering firewall that reassembles fragments before applying rules.
Why this is correct
A packet-filtering firewall evaluates source and destination addresses and ports, and by reassembling fragments before rule evaluation it prevents attackers from splitting a prohibited packet across fragments to evade the filter. This directly implements the requirement to allow only approved subnets to reach TCP port 7000 while closing the fragmentation bypass, making it the most targeted control.
- ✗
An application-layer gateway that decodes the proprietary protocol.
Why it's wrong here
An application-layer gateway inspects and mediates the proprietary protocol's content, which is valuable for detecting malicious commands, but it does not directly restrict which source subnets may reach port 7000. The requirement is a network-layer access restriction that must also handle fragmentation correctly, so protocol decoding alone does not satisfy the stated control objective.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.