Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

⚠ Common exam trap

The trap is including legacy firewall features like static packet filtering or stateful inspection as NGFW characteristics — candidates must distinguish first-, second-, and next-generation firewall capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application identification and control

Option B is correct because an NGFW performs deep packet inspection to identify applications (e.g., via App-ID) and enforce granular control based on the application rather than just port, which is essential against advanced threats that tunnel over allowed ports. Option C is correct because NGFWs integrate with directory services (e.g., Active Directory, LDAP) to map traffic to specific users and groups, enabling identity-based policies that traditional firewalls cannot enforce. Option E is correct because NGFWs bundle an integrated IPS that inspects traffic for known exploit signatures and behavioral anomalies, providing inline threat prevention without a separate appliance. Option A is not correct because static packet filtering based on IP and port is a first-generation firewall capability, not a distinguishing NGFW feature. Option D is not correct because stateful packet inspection is a baseline capability of traditional stateful firewalls and is not unique to NGFWs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Static packet filtering based on IP and port

    Why it's wrong here

    Static packet filtering examines only IP addresses and ports, offering no application identification, user awareness or threat inspection. It is tempting because it is the foundational firewall function, and it would be correct if the scenario required only basic perimeter filtering rather than defence against advanced threats.

  • ✓

    Application identification and control

    Why this is correct

    NGFWs inspect traffic to identify applications regardless of port, then allow, block, or shape them by category. This application-layer control directly addresses advanced threats that tunnel over permitted ports, a capability absent from traditional port-based firewalls.

  • ✓

    User identity awareness

    Why this is correct

    NGFWs extend beyond port and protocol filtering by tying policy to directory users and groups, so rules follow identity rather than IP alone. This identity awareness satisfies the stem's advanced-threat requirement by enforcing consistent policy for roaming and remote users.

  • ✗

    Stateful packet inspection

    Why it's wrong here

    Stateful packet inspection tracks connection state but is a baseline capability of traditional firewalls, not a defining NGFW feature. It is tempting because every NGFW still performs it, and it would be the correct answer if the question asked which feature a conventional stateful firewall provides.

  • ✓

    Integrated intrusion prevention system (IPS)

    Why this is correct

    NGFWs integrate intrusion prevention, inspecting packet payloads for exploit signatures and malicious behaviour and blocking them inline. This deep inspection satisfies the stem's advanced-threat protection requirement, consolidating firewall and IPS functions into a single enforcement point.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.