mediumMultiple Choice
CISSP Practice Question: A remote user at 203.0.113.5 cannot access the…
Exhibit
Refer to the exhibit. The following firewall log entry shows a denied packet: Deny tcp 203.0.113.5 52314 10.0.0.10 443 The firewall has the following ACL applied inbound on the external interface: ip access-list extended INSIDE-IN permit tcp host 203.0.113.2 host 10.0.0.10 eq 443 deny ip any any log
A remote user at 203.0.113.5 cannot access the internal web server at 10.0.0.10 over HTTPS. What is the most likely cause of the denial?
⚠ Common exam trap
Candidates often overthink firewall issues and select complex answers like directionality (Option B) or stateful inspection failures (Option C), when the most common and likely administrative oversight is simply forgetting to add a permit rule for the specific host or subnet in the ACL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ACL is missing a permit rule for the user's IP
The user at 203.0.113.5 is attempting to reach the internal web server over HTTPS (TCP/443). If a firewall with an ACL is implemented to control this traffic, the most direct cause of a silent denial for a specific user is the absence of an explicit permit rule for that user's source IP. Because ACLs process rules sequentially and end with an implicit deny, any traffic not explicitly permitted will be dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ACL is missing a permit rule for the user's IP
Why this is correct
Access Control Lists (ACLs) process rules sequentially, and if no explicit permit rule matches, traffic is implicitly denied by the ACL's default "deny all" at the end. Since the existing permit rule only specifies 203.0.113.2, traffic originating from 203.0.113.5 will not match this specific rule. Consequently, the packet from 203.0.113.5 proceeds to the implicit deny, preventing access to the internal web server.
- ✗
The ACL is applied in the wrong direction
Why it's wrong here
Applying an ACL in the wrong direction would mean it's inspecting traffic leaving the interface when it should be inspecting traffic entering, or vice-versa. For a remote user attempting to access an internal web server, the ACL must be applied inbound on the external interface to filter incoming connection requests from the internet. If it were applied outbound, it would only filter traffic *leaving* the internal network, which is not the issue when a remote user cannot initiate a connection.
- ✗
The firewall is not performing stateful inspection
Why it's wrong here
Stateful inspection primarily tracks established connections, allowing return traffic for previously permitted outbound sessions without needing explicit inbound ACL rules for the return path. However, the initial connection attempt from 203.0.113.5 is being denied by an explicit ACL rule *before* any state could be established. Therefore, the absence of stateful inspection is irrelevant to this initial connection denial, as the ACL is the primary gatekeeper for new sessions.
- ✗
The web server is not listening on port 443
Why it's wrong here
If the web server were not listening on port 443 (or the intended port), the firewall would typically permit the traffic, and the user would receive a "connection refused" message directly from the server, indicating the port is closed or no service is running. The log explicitly states a "deny," which is a firewall action, confirming that the firewall itself is actively blocking the traffic at the network perimeter, not that the server is unavailable or misconfigured.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.