SSCP Network and Communications Security Practice Question
A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?
⚠ Common exam trap
The trap is assuming that a stateful firewall can inspect URLs because it tracks connections, but stateful firewalls only track state at Layers 3-4; application layer inspection requires a proxy or NGFW.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application proxy firewall
An application proxy firewall is correct because it operates at the application layer (Layer 7) and can inspect HTTP/HTTPS traffic to block malicious URLs. It acts as an intermediary, terminating the client connection and initiating a new one to the server, allowing deep inspection of application data. This meets the requirement to inspect application layer data for outbound web traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Application proxy firewall
Why this is correct
An application proxy firewall terminates and inspects traffic at Layer 7, examining HTTP request contents including URLs. This satisfies the requirement to inspect application-layer data and block malicious URLs, which packet-filtering firewalls cannot achieve since they only examine headers.
- ✗
Stateless packet filter
Why it's wrong here
A stateless packet filter examines only headers such as source, destination and port, with no awareness of URLs inside HTTP requests. It is tempting because it is a genuine firewall type, but it would be correct for coarse allow/deny rules, not application-layer inspection.
- ✗
Stateful firewall
Why it's wrong here
Stateful firewalls track connection state at layers 3 and 4, so they cannot inspect URLs or application-layer payloads; blocking malicious URLs requires a next-generation or application-layer firewall with URL filtering. Stateful inspection is the right pick when you only need to permit return traffic for established sessions.
- ✗
Network Access Control (NAC) system
Why it's wrong here
NAC decides whether endpoints may join or access a network, enforcing posture and identity checks at admission; it does not parse HTTP payloads or URLs. It is tempting because NAC sits inline with traffic, but it would be correct for controlling device onboarding, not application-layer inspection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.