mediumMultiple Choice
CISSP Practice Question: Refer to the exhibit
Network Topology
Refer to the exhibit. An application running on this server uses HTTPS (port 443). What is the most likely impact of the current firewall rules on the application?
⚠ Common exam trap
Many candidates assume HTTPS is a subset of HTTP or that allowing HTTP implicitly allows HTTPS, but they are separate TCP ports and require distinct firewall rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Clients will be unable to connect to the application because HTTPS is not explicitly allowed.
The firewall rules only explicitly permit HTTP (port 80) and deny all other traffic by default. HTTPS uses port 443, which is not listed in the permitted rules, so the firewall will block the connection. Without an explicit allow rule for port 443, the application cannot function over HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clients will only be able to connect from IP addresses in the 10.0.0.0/8 range.
Why it's wrong here
The firewall rules, as inferred from the context, indicate that traffic originating from the 10.0.0.0/8 range is specifically targeted for logging or dropping, not for exclusive allowance. If there is a rule to log or drop traffic from this range, it implies a restrictive action, not a permissive one that would limit connections *only* to this range while allowing them. Other IP ranges might be allowed based on other rules, and this specific range is being handled restrictively, preventing connections rather than enabling them exclusively.
- ✗
The application will function normally as HTTP is allowed.
Why it's wrong here
This statement is incorrect because, while the firewall explicitly permits HTTP traffic on port 80, the application itself is stated to utilize HTTPS, which operates on TCP port 443. Since there is no explicit rule allowing HTTPS traffic, and firewalls typically operate on an implicit deny (drop) principle for unlisted services, connections attempting to use port 443 will be blocked. Therefore, the application will not function normally as its required protocol is not allowed to pass through the firewall.
- ✓
Clients will be unable to connect to the application because HTTPS is not explicitly allowed.
Why this is correct
The application relies on HTTPS for client connections, which uses TCP port 443. The firewall rules explicitly allow HTTP on port 80 but do not contain any rule to permit traffic on port 443. Consequently, any connection attempts to the application via HTTPS will be intercepted and blocked by the firewall's implicit deny or default drop policy, preventing clients from establishing a connection to the service.
- ✗
All HTTPS traffic will be logged and then dropped.
Why it's wrong here
The firewall's logging configuration is specific, not universal for all dropped traffic. Based on the inferred rules, only traffic originating from the 10.0.0.0/8 IP range is explicitly configured for logging. While HTTPS traffic (on port 443) will indeed be dropped due to the lack of an explicit allow rule and the default deny policy, there is no corresponding rule to log all such dropped HTTPS connection attempts, only specific source IP ranges.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.