Courseiva
Network Security →easyMultiple Select

ISC2 CC Network Security Practice Question

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tracks connection state

A stateful firewall tracks the state of active connections and can block unsolicited inbound traffic. Packet filtering is stateless, and application inspection is typical of proxy firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inspects application-layer data

    Why it's wrong here

    Application-layer inspection belongs to next-generation or proxy firewalls, which parse payloads up to Layer 7. A stateful firewall tracks connections in its state table using Layer 3 and Layer 4 header information only. Deep packet inspection would be the right answer where filtering must target specific applications or protocols.

  • ✓

    Tracks connection state

    Why this is correct

    A stateful firewall maintains a connection table recording each flow's source, destination and port, so return traffic is matched against established sessions rather than inspected in isolation. This per-session tracking is precisely the defining characteristic the stem asks for, distinguishing it from stateless packet filters that evaluate each packet independently.

  • ✗

    Operates only at Layer 3

    Why it's wrong here

    A stateful firewall inspects Layer 4 headers to maintain its connection state table, so it cannot operate solely at Layer 3. Packet-filtering firewalls work at Layer 3, and a stateless ACL router would be the correct choice where only source and destination IP addresses matter.

  • ✗

    Filters packets based on static rules only

    Why it's wrong here

    Static rule filtering describes stateless packet filtering; a stateful firewall maintains a connection state table and permits return traffic for established sessions. It tempts because static rules still exist within stateful configurations, and static-only filtering is the correct characterisation when the question asks about stateless firewalls.

  • ✓

    Blocks unsolicited inbound traffic by default

    Why this is correct

    Because the connection table records only internally initiated sessions, packets arriving without a matching entry are dropped. This default-deny posture for unsolicited inbound traffic is the second defining characteristic the stem requires, and it follows directly from stateful inspection rather than from any static rule set.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.