easyMultiple Choice
ISC2 CC Practice Question: A network administrator is troubleshooting a…
A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?
⚠ Common exam trap
ISC2 often tests the misconception that a single firewall rule allowing traffic in one direction automatically permits the return traffic, but in stateless firewalls or when stateful inspection is disabled, you must explicitly create a rule for the reverse direction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall is not stateful and does not automatically allow return traffic; a separate rule is needed.
The firewall rule only permits traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. When users in 10.2.2.0/24 initiate a connection to the web server in 10.1.1.0/24, the firewall sees a new session that does not match the existing rule (source/destination reversed). If the firewall is not stateful, it will not automatically allow the return traffic for the reverse direction, and no separate rule exists to permit that traffic, causing the connectivity failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The web server in 10.1.1.0 is blocking the IP range of 10.2.2.0/24.
Why it's wrong here
The server's own filtering cannot explain the failure, because the firewall rule permits only 10.1.1.0/24 to 10.2.2.0/24 on TCP 443; return traffic from 10.2.2.0/24 is never allowed. Host-based blocking is tempting as a general connectivity suspect, but the stem's directional rule already accounts for the symptom.
- ✗
The firewall rule is incorrectly applied to the wrong interface.
Why it's wrong here
Interface binding affects whether a rule is evaluated at all, so a misapplied rule would block both directions, contradicting the working 10.1.1.0/24 traffic. It would be tempting when a rule appears absent from the expected zone, but the asymmetric symptom points to the rule permitting only one direction of the flow.
- ✗
The subnet masks are misconfigured, causing routing issues.
Why it's wrong here
Masks are evidently correct, since 10.1.1.0/24 reaches 10.2.2.10 successfully; routing between the segments therefore already works. Misconfigured masks would break both directions, not one. Mask errors are tempting when a single path fails, but the firewall rule's one-way direction is the actual constraint here.
- ✓
The firewall is not stateful and does not automatically allow return traffic; a separate rule is needed.
Why this is correct
A stateless firewall evaluates each packet against rules independently, so the outbound rule permitting 10.1.1.0/24 to 10.2.2.0/24 on TCP 443 creates no matching inbound permission. Return traffic from 10.2.2.0/24 is dropped, requiring a separate rule for the reverse direction.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.