Courseiva
Network Security →hardMultiple Choice

ISC2 CC Network Security Practice Question

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

⚠ Common exam trap

The trap is conflating 'stateful' with 'next-gen' — candidates pick A or D because they associate advanced inspection with stateful firewalls, but statefulness is specifically about connection tracking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It uses a state table to track connections

A stateful firewall maintains a state table that tracks active connections (source/destination IP, ports, sequence numbers, TCP flags), allowing it to make decisions based on the context of a session rather than each packet in isolation. This lets it automatically permit return traffic for established connections without explicit rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It can decrypt SSL traffic

    Why it's wrong here

    SSL decryption is a separate capability, typically provided by next-generation firewalls performing deep packet inspection, and does not define stateful versus stateless operation. It is tempting because stateful firewalls often include extra features, but a basic stateful firewall tracks TCP sessions without decrypting TLS.

  • ✗

    It examines each packet in isolation

    Why it's wrong here

    Examining each packet in isolation describes stateless filtering, which is precisely what a stateful firewall does not do; it maintains a connection state table tracking sessions. The option is tempting because per-packet inspection is a real firewall behaviour, but it belongs to stateless ACLs, not stateful inspection.

  • ✓

    It uses a state table to track connections

    Why this is correct

    A state table records each flow's source, destination, ports and TCP session state, so return traffic is permitted automatically without a matching inbound rule. Stateless firewalls inspect each packet in isolation against static ACLs, offering no connection awareness. This satisfies the stem's requirement for a distinguishing characteristic.

  • ✗

    It can filter based on application-layer data

    Why it's wrong here

    Application-layer filtering is performed by next-generation or proxy firewalls, not by stateful packet filters, which track connections at layers 3 and 4. It is tempting because stateful devices are often conflated with NGFWs, but the defining stateful characteristic is the connection state table, not payload inspection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.