Courseiva
hardMultiple Choice

SSCP Practice Question: A security analyst discovers that an internal…

A security analyst discovers that an internal host is sending traffic to an external IP address known to be a command-and-control server. The analyst wants to block only that specific traffic without affecting other traffic. Which firewall rule should be implemented?

⚠ Common exam trap

Candidates often choose a broad deny rule (like denying all traffic to the external IP) because they focus on the malicious destination, forgetting that such a rule would block all traffic to that IP from any source, potentially impacting other hosts or services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny traffic from the internal host to the external IP.

It creates a specific deny rule that matches only the source IP of the internal host and the destination IP of the command-and-control server, blocking that exact traffic flow while allowing all other traffic to and from both hosts. This is the most precise and least disruptive approach, adhering to the principle of least privilege in firewall rule design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny all traffic from the internal host.

    Why it's wrong here

    Denying all traffic from the internal host blocks every service that host uses, not just the command-and-control session, causing widespread disruption. It is tempting because it guarantees the malicious traffic stops, and would be correct when the host is confirmed compromised and must be fully quarantined from the network pending remediation.

  • ✗

    Deny all traffic to the external IP.

    Why it's wrong here

    Denying all traffic to that external IP blocks every internal host reaching it, which is broader than the single host-to-server flow described. It is tempting because it neutralises the command-and-control endpoint itself, and would be correct when the address is confirmed malicious and no legitimate internal system should ever contact it.

  • ✗

    Deny traffic on the specific port used.

    Why it's wrong here

    Port-based denial blocks every flow traversing that port, not the single malicious destination, so legitimate services on the same port are also dropped. It is tempting because port filtering is a core firewall function, and it would be the right rule when an unwanted service itself must be disabled across all hosts.

  • ✓

    Deny traffic from the internal host to the external IP.

    Why this is correct

    A rule matching both source internal host and destination external IP denies only that specific flow, leaving all other traffic unaffected. This satisfies the constraint of blocking solely the command-and-control communication, whereas broader subnet or port blocks would disrupt unrelated legitimate traffic.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.