ISC2 CC Network Security Practice Question
An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
⚠ Common exam trap
The trap is confusing a stateful firewall with a WAF; candidates assume 'firewall' means it inspects everything, but only a WAF understands HTTP/HTTPS application-layer content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web Application Firewall (WAF)
A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at Layer 7 and applies rules to block attacks like SQL injection, cross-site scripting (XSS), and malicious bots. It understands web protocols and can examine request bodies, headers, and cookies, which is exactly what is needed to protect internal web applications exposed to external users. This makes WAF the purpose-built device for the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stateful firewall
Why it's wrong here
A stateful firewall tracks connection state but still decides on Layer 3/4 header and session information, not HTTP/HTTPS content, so it cannot block malicious requests inside encrypted or application-layer traffic. It is tempting because it is a firewall, and it would be correct for controlling established TCP sessions by port and state.
- ✓
Web Application Firewall (WAF)
Why this is correct
A Web Application Firewall operates at Layer 7, inspecting HTTP/HTTPS request content against rule sets to block SQL injection, cross-site scripting and similar exploits. This directly satisfies the stem's requirement to inspect web traffic and block malicious requests, unlike packet-filtering firewalls that cannot parse application payloads.
- ✗
Intrusion Detection System (IDS)
Why it's wrong here
An IDS passively copies traffic and raises alerts; it does not sit inline to block malicious HTTP/HTTPS requests, so it cannot enforce the stated requirement. It is tempting because signature-based detection genuinely inspects application payloads, and an IDS is the correct choice when the goal is monitoring and alerting rather than prevention.
- ✗
Packet filtering firewall
Why it's wrong here
A packet-filtering firewall evaluates only headers such as source/destination IP, port and protocol, so it cannot inspect HTTP/HTTPS payloads or identify malicious requests. It is tempting because it does filter traffic, and it would be correct where simple ACL-style permit/deny rules on addresses and ports suffice.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
Terminal Access Controller Access-control System
TACACS+ is a remote authentication protocol that uses three separate servers to verify who you are, what you are allowed to do, and record what you did on network devices.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.