Courseiva
hardMultiple Select

ISC2 CC Practice Question: Which THREE of the following are characteristics…

Which THREE of the following are characteristics of a stateful firewall? (Select exactly three.)

⚠ Common exam trap

ISC2 often tests the distinction between stateful and stateless firewalls, and the trap here is that candidates confuse 'stateful' with 'application-layer inspection,' leading them to select option C, when in fact stateful firewalls only track session state at Layers 3 and 4, not the application payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It can automatically allow return traffic for outbound connections

Option A is correct because a stateful firewall tracks the connection state and can automatically permit return traffic for sessions initiated from inside the trusted network, rather than requiring a separate inbound rule. Option B is correct because the core mechanism of a stateful firewall is a state table (connection table) that records active sessions, including source/destination IPs, ports, sequence numbers, and TCP flags. Option E is correct because stateful firewalls make filtering decisions based on the context of the traffic flow, such as whether a packet belongs to an established, related, or new connection, rather than evaluating each packet in isolation. Option C is not correct here because application-layer payload inspection is characteristic of an application-layer firewall or next-generation firewall (NGFW) with deep packet inspection, not a defining feature of a basic stateful firewall. Option D is not correct because filtering solely on source/destination IP and port describes a stateless packet-filtering firewall, which does not maintain connection state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It can automatically allow return traffic for outbound connections

    Why this is correct

    A stateful firewall tracks connection state, so return traffic matching an existing session in its state table is permitted automatically without an explicit inbound rule. This is the defining behavioural difference from stateless packet filtering.

  • ✓

    It maintains a state table of active connections

    Why this is correct

    A stateful firewall builds and maintains a state table recording each active connection's source, destination, ports and session status. Every packet is checked against this table, enabling session-aware decisions rather than evaluating each packet in isolation.

  • ✗

    It inspects application-layer payloads

    Why it's wrong here

    Application-layer payload inspection belongs to a next-generation or application firewall, operating at Layer 7. It tempts because stateful firewalls track Layer 4 sessions, but they do not parse payload content; that deeper inspection is a separate capability, not a stateful characteristic.

  • ✗

    It filters packets based solely on source/destination IP and port

    Why it's wrong here

    Stateless packet filtering by IP and port alone is the defining behaviour of a packet-filtering firewall, which examines each packet in isolation. It tempts because stateful firewalls do read those headers, but they additionally maintain a connection state table tracking sessions, which this option omits entirely.

  • ✓

    It makes filtering decisions based on the context of traffic flows

    Why this is correct

    Stateful firewalls maintain a connection state table, tracking each flow's source, destination, ports and sequence. Decisions therefore reflect the established session context rather than inspecting packets in isolation, which is precisely the flow-context characteristic the question demands.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.