ISC2 CC Network Security Practice Question
A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?
⚠ Common exam trap
CC often tests whether candidates know that only NGFWs (and dedicated TLS inspection appliances) can decrypt and re-encrypt SSL/TLS — candidates may incorrectly attribute this to application proxy or stateful inspection firewalls because those sound more 'advanced.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Next-generation firewall (NGFW)
A Next-Generation Firewall (NGFW) includes SSL/TLS decryption and inspection capabilities, allowing it to decrypt encrypted traffic, inspect the plaintext for threats or policy violations, and then re-encrypt it before forwarding. This is a defining feature that separates NGFWs from traditional firewalls. The other firewall types lack the deep packet inspection and decryption engine required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application proxy firewall
Why it's wrong here
An application proxy firewall operates at the application layer but does not itself terminate and re-establish TLS sessions to inspect encrypted payloads. It is tempting because it understands application protocols, yet the architecture that decrypts, inspects and re-encrypts traffic is a TLS/SSL interception or decryption gateway.
- ✗
Packet filtering firewall
Why it's wrong here
Packet filtering examines individual packet headers against ACLs and never decrypts payloads, so TLS content stays opaque. It is tempting as the simplest, fastest filtering method, and it would be correct for basic IP and port blocking, but the scenario requires decrypting, inspecting and re-encrypting SSL/TLS traffic.
- ✓
Next-generation firewall (NGFW)
Why this is correct
A next-generation firewall performs SSL/TLS inspection by acting as a man-in-the-middle proxy: it decrypts traffic using a trusted certificate, examines payloads for threats and policy violations, then re-encrypts before forwarding. This satisfies the stem's requirement for content inspection of encrypted sessions, which traditional packet-filtering or stateful firewalls cannot achieve.
- ✗
Stateful inspection firewall
Why it's wrong here
Stateful inspection tracks connection state and packet context but reads only packet headers, leaving TLS payloads encrypted. It is tempting because it is the mainstream enterprise firewall, and it would be correct for filtering based on sessions and ports, but it cannot decrypt, inspect and re-encrypt SSL/TLS content.
Go deeper
Related to this question
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
Key term
Decryption
Decryption is the process of converting encrypted or scrambled data back into its original, readable form using a specific key or method.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.