Courseiva

CISSP Communication and Network Security Practice Question

Which type of firewall operates at Layer 7 and can inspect application payloads, such as blocking specific SQL commands or HTTP methods?

⚠ Common exam trap

Test-takers frequently confuse 'stateful inspection' (Layer 4) with application-layer inspection, assuming stateful firewalls can inspect payloads, but they only track session state, not application content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application proxy

An application proxy firewall (also known as an application-level gateway) operates at Layer 7 (Application Layer) of the OSI model. It can inspect the full application payload, allowing it to block specific SQL commands, HTTP methods (e.g., PUT, DELETE), or other application-layer content by terminating the connection and re-establishing it after deep inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stateful inspection

    Why it's wrong here

    Stateful inspection tracks connection state in a Layer 3/4 state table, permitting return traffic for established sessions, but it does not decode HTTP methods or SQL statements. It is tempting because it improves on static packet filtering, and would be correct where the requirement is stateful connection tracking rather than Layer 7 payload inspection.

  • ✓

    Application proxy

    Why this is correct

    An application proxy terminates the client connection and rebuilds it to the server, fully parsing Layer 7 payloads. This lets it inspect HTTP methods and SQL statements and block specific commands, satisfying the requirement to filter application content rather than merely ports and addresses.

  • ✗

    Packet filter

    Why it's wrong here

    Packet filters examine Layer 3/4 headers only — source and destination IP addresses, ports and protocol flags — so SQL commands and HTTP verbs inside the payload remain invisible. They are tempting because they are fast and cheap, and would be correct where the requirement is blocking traffic by address or port rather than inspecting application content.

  • ✗

    Circuit-level gateway

    Why it's wrong here

    Circuit-level gateways validate TCP handshakes and session legitimacy at Layer 5, so they never parse HTTP methods or SQL syntax; payload inspection is impossible. They are tempting because they cheaply hide internal hosts and block unsolicited connections, and would be the right pick when the requirement is session-level filtering rather than application content.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.