CISSP Communication and Network Security Practice Question
Which type of firewall operates at Layer 7 and can inspect application payloads, such as blocking specific SQL commands or HTTP methods?
⚠ Common exam trap
Test-takers frequently confuse 'stateful inspection' (Layer 4) with application-layer inspection, assuming stateful firewalls can inspect payloads, but they only track session state, not application content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application proxy
An application proxy firewall (also known as an application-level gateway) operates at Layer 7 (Application Layer) of the OSI model. It can inspect the full application payload, allowing it to block specific SQL commands, HTTP methods (e.g., PUT, DELETE), or other application-layer content by terminating the connection and re-establishing it after deep inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stateful inspection
Why it's wrong here
Stateful inspection tracks connection state in a Layer 3/4 state table, permitting return traffic for established sessions, but it does not decode HTTP methods or SQL statements. It is tempting because it improves on static packet filtering, and would be correct where the requirement is stateful connection tracking rather than Layer 7 payload inspection.
- ✓
Application proxy
Why this is correct
An application proxy terminates the client connection and rebuilds it to the server, fully parsing Layer 7 payloads. This lets it inspect HTTP methods and SQL statements and block specific commands, satisfying the requirement to filter application content rather than merely ports and addresses.
- ✗
Packet filter
Why it's wrong here
Packet filters examine Layer 3/4 headers only — source and destination IP addresses, ports and protocol flags — so SQL commands and HTTP verbs inside the payload remain invisible. They are tempting because they are fast and cheap, and would be correct where the requirement is blocking traffic by address or port rather than inspecting application content.
- ✗
Circuit-level gateway
Why it's wrong here
Circuit-level gateways validate TCP handshakes and session legitimacy at Layer 5, so they never parse HTTP methods or SQL syntax; payload inspection is impossible. They are tempting because they cheaply hide internal hosts and block unsolicited connections, and would be the right pick when the requirement is session-level filtering rather than application content.
Go deeper
Related to this question
Key term
OSI model
The OSI model is a conceptual framework that standardizes the functions of a telecommunication or computing system into seven distinct layers, from physical hardware to application software.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.