ISC2 CC Network Security Practice Question
An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)
⚠ Common exam trap
The trap is including legacy firewall features like static packet filtering or stateful inspection as NGFW characteristics — candidates must distinguish first-, second-, and next-generation firewall capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application identification and control
Option B is correct because an NGFW performs deep packet inspection to identify applications (e.g., via App-ID) and enforce granular control based on the application rather than just port, which is essential against advanced threats that tunnel over allowed ports. Option C is correct because NGFWs integrate with directory services (e.g., Active Directory, LDAP) to map traffic to specific users and groups, enabling identity-based policies that traditional firewalls cannot enforce. Option E is correct because NGFWs bundle an integrated IPS that inspects traffic for known exploit signatures and behavioral anomalies, providing inline threat prevention without a separate appliance. Option A is not correct because static packet filtering based on IP and port is a first-generation firewall capability, not a distinguishing NGFW feature. Option D is not correct because stateful packet inspection is a baseline capability of traditional stateful firewalls and is not unique to NGFWs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static packet filtering based on IP and port
Why it's wrong here
Static packet filtering examines only IP addresses and ports, offering no application identification, user awareness or threat inspection. It is tempting because it is the foundational firewall function, and it would be correct if the scenario required only basic perimeter filtering rather than defence against advanced threats.
- ✓
Application identification and control
Why this is correct
NGFWs inspect traffic to identify applications regardless of port, then allow, block, or shape them by category. This application-layer control directly addresses advanced threats that tunnel over permitted ports, a capability absent from traditional port-based firewalls.
- ✓
User identity awareness
Why this is correct
NGFWs extend beyond port and protocol filtering by tying policy to directory users and groups, so rules follow identity rather than IP alone. This identity awareness satisfies the stem's advanced-threat requirement by enforcing consistent policy for roaming and remote users.
- ✗
Stateful packet inspection
Why it's wrong here
Stateful packet inspection tracks connection state but is a baseline capability of traditional firewalls, not a defining NGFW feature. It is tempting because every NGFW still performs it, and it would be the correct answer if the question asked which feature a conventional stateful firewall provides.
- ✓
Integrated intrusion prevention system (IPS)
Why this is correct
NGFWs integrate intrusion prevention, inspecting packet payloads for exploit signatures and malicious behaviour and blocking them inline. This deep inspection satisfies the stem's advanced-threat protection requirement, consolidating firewall and IPS functions into a single enforcement point.
Visual reference
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Baseline
A baseline is a documented starting point for the normal performance and behavior of a system, network, or component, used to detect changes and troubleshoot issues.
Key term
Terminal Access Controller Access-control System
TACACS+ is a remote authentication protocol that uses three separate servers to verify who you are, what you are allowed to do, and record what you did on network devices.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.