Courseiva

SSCP Network and Communications Security Practice Question

A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?

⚠ Common exam trap

The trap is assuming that a stateful firewall can inspect URLs because it tracks connections, but stateful firewalls only track state at Layers 3-4; application layer inspection requires a proxy or NGFW.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application proxy firewall

An application proxy firewall is correct because it operates at the application layer (Layer 7) and can inspect HTTP/HTTPS traffic to block malicious URLs. It acts as an intermediary, terminating the client connection and initiating a new one to the server, allowing deep inspection of application data. This meets the requirement to inspect application layer data for outbound web traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application proxy firewall

    Why this is correct

    An application proxy firewall terminates and inspects traffic at Layer 7, examining HTTP request contents including URLs. This satisfies the requirement to inspect application-layer data and block malicious URLs, which packet-filtering firewalls cannot achieve since they only examine headers.

  • ✗

    Stateless packet filter

    Why it's wrong here

    A stateless packet filter examines only headers such as source, destination and port, with no awareness of URLs inside HTTP requests. It is tempting because it is a genuine firewall type, but it would be correct for coarse allow/deny rules, not application-layer inspection.

  • ✗

    Stateful firewall

    Why it's wrong here

    Stateful firewalls track connection state at layers 3 and 4, so they cannot inspect URLs or application-layer payloads; blocking malicious URLs requires a next-generation or application-layer firewall with URL filtering. Stateful inspection is the right pick when you only need to permit return traffic for established sessions.

  • ✗

    Network Access Control (NAC) system

    Why it's wrong here

    NAC decides whether endpoints may join or access a network, enforcing posture and identity checks at admission; it does not parse HTTP payloads or URLs. It is tempting because NAC sits inline with traffic, but it would be correct for controlling device onboarding, not application-layer inspection.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.