Courseiva
Communication and Network SecuritymediumMultiple ChoiceObjective-mapped

CISSP Communication and Network Security Practice Question

Which type of firewall can inspect the contents of application-layer traffic, such as HTTP requests, and block malicious payloads?

⚠ Common exam trap

Candidates often confuse a stateful inspection firewall (which tracks connection state) with an application proxy firewall, mistakenly believing that stateful inspection includes deep payload analysis, when in fact stateful inspection only monitors packet headers and connection state at Layers 3 and 4.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Application proxy firewall

An application proxy firewall (also known as an application-level gateway) operates at Layer 7 of the OSI model and can fully inspect the content of application-layer protocols such as HTTP, FTP, and SMTP. By terminating the client connection and establishing a separate connection to the server, it can parse and validate the payload—for example, examining HTTP request bodies for SQL injection strings or malicious scripts—and block them before they reach the internal server. This deep inspection capability distinguishes it from lower-layer firewalls that only examine headers or connection states.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Packet filter firewall

    Why it's wrong here

    A packet filter firewall operates primarily at the network (Layer 3) and transport (Layer 4) layers of the OSI model. It makes filtering decisions based solely on header information, such as source/destination IP addresses, port numbers, and protocol types. This type of firewall cannot inspect the actual data payload within the packets, meaning it has no understanding of application-layer content or commands.

  • Circuit-level gateway

    Why it's wrong here

    A circuit-level gateway functions at the session layer (Layer 5) by establishing a virtual circuit between internal and external hosts. It monitors the setup and teardown of TCP or UDP sessions, ensuring valid connections. However, once a circuit is established, it relays traffic without inspecting the application-layer payload, effectively acting as a proxy for the connection itself rather than the data content.

  • Application proxy firewall

    Why this is correct

    An application proxy firewall, also known as a Layer 7 firewall, acts as a full intermediary for specific application protocols. It terminates both the client's and the server's connections, completely parsing and re-establishing them. This deep inspection allows it to fully understand, filter, and even modify application-layer commands and data, providing granular control and robust security against application-specific attacks.

  • Stateful inspection firewall

    Why it's wrong here

    A stateful inspection firewall enhances packet filtering by maintaining a state table that tracks active connections. It can determine if incoming packets are part of an established, legitimate session, allowing return traffic to pass without explicit rules. While it understands connection context and can detect certain anomalies, it primarily inspects Layer 3 and 4 headers and does not perform deep content inspection of the application-layer payload.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.