Courseiva

SSCP Network and Communications Security Practice Question

A company wants to implement a firewall that can track the state of network connections and make decisions based on the context of traffic (e.g., allowing return packets for an established connection). Which type of firewall should they choose?

⚠ Common exam trap

SSCP often tests the distinction between stateless packet filters (per-packet ACLs) and stateful firewalls (connection tracking) — the trap is picking NGFW because it sounds more advanced, but the question's defining criterion is state tracking, which is the stateful firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stateful firewall

A stateful firewall tracks the state of network connections in a state table, allowing return packets for established sessions without requiring explicit inbound rules. This context-aware behavior is exactly what the question describes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application proxy firewall

    Why it's wrong here

    An application proxy firewall inspects Layer 7 application payloads and terminates client sessions, so it cannot track TCP connection state or permit return packets for established flows. It is tempting because proxies do provide deep content inspection and user-level control, which suits filtering specific applications rather than stateful packet handling.

  • ✗

    Stateless packet filter

    Why it's wrong here

    A stateless packet filter evaluates each packet against static rules independently, so it cannot recognise return traffic as part of an established session and would require permissive rules for reply ports. It is tempting for its speed and simplicity, and suits simple filtering where no session tracking is needed.

  • ✗

    Next-generation firewall

    Why it's wrong here

    A next-generation firewall does track connection state, but it is defined by added application-layer inspection, intrusion prevention and user awareness, so it satisfies the requirement while exceeding it. It is tempting as the modern default, and would be correct where deep packet inspection or application control is also required.

  • ✓

    Stateful firewall

    Why this is correct

    A stateful firewall maintains a connection state table, tracking each session's source, destination and sequence so return packets for established connections are permitted automatically. This context-aware inspection satisfies the requirement, unlike stateless packet filtering, which evaluates each packet in isolation.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.