Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?

⚠ Common exam trap

The trap here is assuming that any firewall or IPS automatically defeats fragmentation evasion, when reassembly before rule evaluation is a specific capability that must be confirmed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A packet-filtering firewall that reassembles fragments before applying rules.

The requirement is deterministic network-layer access control on a specific port combined with protection against fragmentation evasion. A packet-filtering firewall that reassembles fragments before applying rules does exactly that, whereas application gateways, stateful inspection, and intrusion prevention systems address different concerns and do not guarantee both the source restriction and the anti-fragmentation behavior in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A stateful inspection firewall that tracks established TCP sessions.

    Why it's wrong here

    Stateful inspection tracks connection state so return traffic is permitted without an explicit rule, which improves accuracy for established sessions, but it does not by itself guarantee that fragmented packets are reassembled and checked against the source-subnet rule. The scenario specifically calls out fragmentation evasion, so a control focused on session state does not fully address the requirement.

  • ✗

    A network intrusion prevention system tuned to the trading protocol.

    Why it's wrong here

    A network intrusion prevention system detects and blocks known malicious patterns in traffic, but it is not the primary mechanism for enforcing source-subnet allow lists on a specific TCP port. It also may not reliably reassemble fragments before detection, so it does not provide the deterministic access control and anti-evasion guarantee the firm requires.

  • ✓

    A packet-filtering firewall that reassembles fragments before applying rules.

    Why this is correct

    A packet-filtering firewall evaluates source and destination addresses and ports, and by reassembling fragments before rule evaluation it prevents attackers from splitting a prohibited packet across fragments to evade the filter. This directly implements the requirement to allow only approved subnets to reach TCP port 7000 while closing the fragmentation bypass, making it the most targeted control.

  • ✗

    An application-layer gateway that decodes the proprietary protocol.

    Why it's wrong here

    An application-layer gateway inspects and mediates the proprietary protocol's content, which is valuable for detecting malicious commands, but it does not directly restrict which source subnets may reach port 7000. The requirement is a network-layer access restriction that must also handle fragmentation correctly, so protocol decoding alone does not satisfy the stated control objective.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.