ISC2 CC Network Security Practice Question
Which two of the following are characteristics of a stateful firewall? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tracks connection state
A stateful firewall tracks the state of active connections and can block unsolicited inbound traffic. Packet filtering is stateless, and application inspection is typical of proxy firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inspects application-layer data
Why it's wrong here
Application-layer inspection belongs to next-generation or proxy firewalls, which parse payloads up to Layer 7. A stateful firewall tracks connections in its state table using Layer 3 and Layer 4 header information only. Deep packet inspection would be the right answer where filtering must target specific applications or protocols.
- ✓
Tracks connection state
Why this is correct
A stateful firewall maintains a connection table recording each flow's source, destination and port, so return traffic is matched against established sessions rather than inspected in isolation. This per-session tracking is precisely the defining characteristic the stem asks for, distinguishing it from stateless packet filters that evaluate each packet independently.
- ✗
Operates only at Layer 3
Why it's wrong here
A stateful firewall inspects Layer 4 headers to maintain its connection state table, so it cannot operate solely at Layer 3. Packet-filtering firewalls work at Layer 3, and a stateless ACL router would be the correct choice where only source and destination IP addresses matter.
- ✗
Filters packets based on static rules only
Why it's wrong here
Static rule filtering describes stateless packet filtering; a stateful firewall maintains a connection state table and permits return traffic for established sessions. It tempts because static rules still exist within stateful configurations, and static-only filtering is the correct characterisation when the question asks about stateless firewalls.
- ✓
Blocks unsolicited inbound traffic by default
Why this is correct
Because the connection table records only internally initiated sessions, packets arriving without a matching entry are dropped. This default-deny posture for unsolicited inbound traffic is the second defining characteristic the stem requires, and it follows directly from stateful inspection rather than from any static rule set.
Visual reference
Go deeper
Related to this question
Key term
Proxy
A proxy is an intermediary server that sits between a client and a destination server, forwarding requests and responses while providing security, privacy, and control.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.