Courseiva
easyMultiple Choice

ISC2 CC Practice Question: A network administrator is troubleshooting a…

A network administrator is troubleshooting a connectivity issue between two segments separated by a firewall. The firewall rule allows traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. Users in 10.1.1.0/24 can access the web server at 10.2.2.10, but users in 10.2.2.0/24 cannot access a web server in 10.1.1.0/24. What is the most likely cause?

⚠ Common exam trap

ISC2 often tests the misconception that a single firewall rule allowing traffic in one direction automatically permits the return traffic, but in stateless firewalls or when stateful inspection is disabled, you must explicitly create a rule for the reverse direction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall is not stateful and does not automatically allow return traffic; a separate rule is needed.

The firewall rule only permits traffic from 10.1.1.0/24 to 10.2.2.0/24 on TCP 443. When users in 10.2.2.0/24 initiate a connection to the web server in 10.1.1.0/24, the firewall sees a new session that does not match the existing rule (source/destination reversed). If the firewall is not stateful, it will not automatically allow the return traffic for the reverse direction, and no separate rule exists to permit that traffic, causing the connectivity failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The web server in 10.1.1.0 is blocking the IP range of 10.2.2.0/24.

    Why it's wrong here

    The server's own filtering cannot explain the failure, because the firewall rule permits only 10.1.1.0/24 to 10.2.2.0/24 on TCP 443; return traffic from 10.2.2.0/24 is never allowed. Host-based blocking is tempting as a general connectivity suspect, but the stem's directional rule already accounts for the symptom.

  • ✗

    The firewall rule is incorrectly applied to the wrong interface.

    Why it's wrong here

    Interface binding affects whether a rule is evaluated at all, so a misapplied rule would block both directions, contradicting the working 10.1.1.0/24 traffic. It would be tempting when a rule appears absent from the expected zone, but the asymmetric symptom points to the rule permitting only one direction of the flow.

  • ✗

    The subnet masks are misconfigured, causing routing issues.

    Why it's wrong here

    Masks are evidently correct, since 10.1.1.0/24 reaches 10.2.2.10 successfully; routing between the segments therefore already works. Misconfigured masks would break both directions, not one. Mask errors are tempting when a single path fails, but the firewall rule's one-way direction is the actual constraint here.

  • ✓

    The firewall is not stateful and does not automatically allow return traffic; a separate rule is needed.

    Why this is correct

    A stateless firewall evaluates each packet against rules independently, so the outbound rule permitting 10.1.1.0/24 to 10.2.2.0/24 on TCP 443 creates no matching inbound permission. Return traffic from 10.2.2.0/24 is dropped, requiring a separate rule for the reverse direction.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.