ISC2 CC Network Security Practice Question
An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web Application Firewall (WAF)
A Web Application Firewall (WAF) is specialized for filtering HTTP/HTTPS traffic and protecting web applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stateful firewall
Why it's wrong here
Stateful firewalls track connections but lack deep application inspection for web attacks.
- ✓
Web Application Firewall (WAF)
Why this is correct
WAF inspects HTTP/HTTPS and filters malicious payloads like SQL injection.
- ✗
Intrusion Detection System (IDS)
Why it's wrong here
IDS monitors and alerts but does not specifically filter web traffic.
- ✗
Packet filtering firewall
Why it's wrong here
Packet filtering operates at L3/4 and cannot inspect application content.
Visual reference
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Terminal Access Controller Access Control System Plus
TACACS+ is a network security protocol that separates authentication, authorization, and accounting to control who can access network devices and what they can do.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.