Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

⚠ Common exam trap

The trap is confusing a stateful firewall with a WAF; candidates assume 'firewall' means it inspects everything, but only a WAF understands HTTP/HTTPS application-layer content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web Application Firewall (WAF)

A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at Layer 7 and applies rules to block attacks like SQL injection, cross-site scripting (XSS), and malicious bots. It understands web protocols and can examine request bodies, headers, and cookies, which is exactly what is needed to protect internal web applications exposed to external users. This makes WAF the purpose-built device for the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stateful firewall

    Why it's wrong here

    A stateful firewall tracks connection state but still decides on Layer 3/4 header and session information, not HTTP/HTTPS content, so it cannot block malicious requests inside encrypted or application-layer traffic. It is tempting because it is a firewall, and it would be correct for controlling established TCP sessions by port and state.

  • ✓

    Web Application Firewall (WAF)

    Why this is correct

    A Web Application Firewall operates at Layer 7, inspecting HTTP/HTTPS request content against rule sets to block SQL injection, cross-site scripting and similar exploits. This directly satisfies the stem's requirement to inspect web traffic and block malicious requests, unlike packet-filtering firewalls that cannot parse application payloads.

  • ✗

    Intrusion Detection System (IDS)

    Why it's wrong here

    An IDS passively copies traffic and raises alerts; it does not sit inline to block malicious HTTP/HTTPS requests, so it cannot enforce the stated requirement. It is tempting because signature-based detection genuinely inspects application payloads, and an IDS is the correct choice when the goal is monitoring and alerting rather than prevention.

  • ✗

    Packet filtering firewall

    Why it's wrong here

    A packet-filtering firewall evaluates only headers such as source/destination IP, port and protocol, so it cannot inspect HTTP/HTTPS payloads or identify malicious requests. It is tempting because it does filter traffic, and it would be correct where simple ACL-style permit/deny rules on addresses and ports suffice.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.