hardMultiple Select
ISC2 CC Practice Question: Which THREE of the following are characteristics…
Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)
⚠ Common exam trap
ISC2 often tests the distinction between stateful and stateless firewalls, and the trap here is that candidates confuse 'stateful' with 'application-layer inspection,' leading them to select option C, when in fact stateful firewalls only track session state at Layers 3 and 4, not the application payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It can automatically allow return traffic for outbound connections
Option A is correct because a stateful firewall tracks the connection state and can automatically permit return traffic for sessions initiated from inside the trusted network, rather than requiring a separate inbound rule. Option B is correct because the core mechanism of a stateful firewall is a state table (connection table) that records active sessions, including source/destination IPs, ports, sequence numbers, and TCP flags. Option E is correct because stateful firewalls make filtering decisions based on the context of the traffic flow, such as whether a packet belongs to an established, related, or new connection, rather than evaluating each packet in isolation. Option C is not correct here because application-layer payload inspection is characteristic of an application-layer firewall or next-generation firewall (NGFW) with deep packet inspection, not a defining feature of a basic stateful firewall. Option D is not correct because filtering solely on source/destination IP and port describes a stateless packet-filtering firewall, which does not maintain connection state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It can automatically allow return traffic for outbound connections
Why this is correct
A stateful firewall tracks connection state, so return traffic matching an existing session in its state table is permitted automatically without an explicit inbound rule. This is the defining behavioural difference from stateless packet filtering.
- ✓
It maintains a state table of active connections
Why this is correct
A stateful firewall builds and maintains a state table recording each active connection's source, destination, ports and session status. Every packet is checked against this table, enabling session-aware decisions rather than evaluating each packet in isolation.
- ✗
It inspects application-layer payloads
Why it's wrong here
Application-layer payload inspection belongs to a next-generation or application firewall, operating at Layer 7. It tempts because stateful firewalls track Layer 4 sessions, but they do not parse payload content; that deeper inspection is a separate capability, not a stateful characteristic.
- ✗
It filters packets based solely on source/destination IP and port
Why it's wrong here
Stateless packet filtering by IP and port alone is the defining behaviour of a packet-filtering firewall, which examines each packet in isolation. It tempts because stateful firewalls do read those headers, but they additionally maintain a connection state table tracking sessions, which this option omits entirely.
- ✓
It makes filtering decisions based on the context of traffic flows
Why this is correct
Stateful firewalls maintain a connection state table, tracking each flow's source, destination, ports and sequence. Decisions therefore reflect the established session context rather than inspecting packets in isolation, which is precisely the flow-context characteristic the question demands.
Visual reference
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.