Courseiva
mediumMultiple Choice

SSCP Practice Question: A network administrator needs to ensure that…

A network administrator needs to ensure that internal users can access only approved external websites. Which technology should be implemented?

⚠ Common exam trap

ISC2 often tests the misconception that an IPS or firewall can perform URL filtering, but these devices typically filter based on IP/port/application signatures, not full URL paths or content categories, which is the specific function of a web proxy with content filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Web Proxy with content filtering

A web proxy with content filtering intercepts HTTP/HTTPS requests from internal users and applies policy rules (e.g., URL whitelists, category blocking) to allow only approved external websites. This technology operates at the application layer, inspecting the full URL and content, making it the correct choice for granular access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Web Proxy with content filtering

    Why this is correct

    A web proxy with content filtering intercepts outbound HTTP and HTTPS requests, evaluating each destination against approved categories and blocking unapproved sites. This enforces the allow-list requirement for internal users, unlike firewalls that filter by IP or port alone.

  • ✗

    Intrusion Prevention System (IPS)

    Why it's wrong here

    An IPS inspects traffic for known attack signatures and malicious patterns, blocking exploits rather than enforcing an allow-list of permitted domains. It is tempting because it sits inline and can drop traffic, but it is the correct choice for detecting and stopping intrusions, not for controlling which websites users may visit.

  • ✗

    Virtual Private Network (VPN)

    Why it's wrong here

    A VPN encrypts traffic between a remote endpoint and the corporate network; it secures the transport but does not evaluate which external websites a user requests. It is tempting because it governs external connectivity, yet it is the right choice for securing remote access to internal resources, not for restricting outbound browsing.

  • ✗

    Network Address Translation (NAT)

    Why it's wrong here

    NAT translates private addresses to public ones for outbound connectivity; it rewrites addressing and performs no URL or domain inspection, so unapproved sites remain reachable. It is tempting because it mediates all internet traffic, but it is designed for address conservation and hiding internal topology, not for filtering destinations.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.