ISC2 CC Network Security Practice Question
Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?
⚠ Common exam trap
The trap is conflating 'stateful' with 'next-gen' — candidates pick A or D because they associate advanced inspection with stateful firewalls, but statefulness is specifically about connection tracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It uses a state table to track connections
A stateful firewall maintains a state table that tracks active connections (source/destination IP, ports, sequence numbers, TCP flags), allowing it to make decisions based on the context of a session rather than each packet in isolation. This lets it automatically permit return traffic for established connections without explicit rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It can decrypt SSL traffic
Why it's wrong here
SSL decryption is a separate capability, typically provided by next-generation firewalls performing deep packet inspection, and does not define stateful versus stateless operation. It is tempting because stateful firewalls often include extra features, but a basic stateful firewall tracks TCP sessions without decrypting TLS.
- ✗
It examines each packet in isolation
Why it's wrong here
Examining each packet in isolation describes stateless filtering, which is precisely what a stateful firewall does not do; it maintains a connection state table tracking sessions. The option is tempting because per-packet inspection is a real firewall behaviour, but it belongs to stateless ACLs, not stateful inspection.
- ✓
It uses a state table to track connections
Why this is correct
A state table records each flow's source, destination, ports and TCP session state, so return traffic is permitted automatically without a matching inbound rule. Stateless firewalls inspect each packet in isolation against static ACLs, offering no connection awareness. This satisfies the stem's requirement for a distinguishing characteristic.
- ✗
It can filter based on application-layer data
Why it's wrong here
Application-layer filtering is performed by next-generation or proxy firewalls, not by stateful packet filters, which track connections at layers 3 and 4. It is tempting because stateful devices are often conflated with NGFWs, but the defining stateful characteristic is the connection state table, not payload inspection.
Visual reference
Go deeper
Related to this question
Key term
Isolation
Isolation is the process of separating a compromised or suspicious system from a network to prevent the spread of malware or unauthorized access.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.