hardMultiple Choice
SSCP Practice Question: Based on the exhibit, which of the following best…
Network Topology
Based on the exhibit, which of the following best describes the firewall configuration?
⚠ Common exam trap
The trap here is that candidates often overlook the implicit deny at the end of an ACL, assuming that only the listed permits exist and that all other traffic is allowed by default, rather than understanding that any traffic not explicitly permitted is dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall allows SSH, HTTP, and HTTPS from the internal subnet and drops all other traffic.
The exhibit shows an access control list (ACL) that explicitly permits TCP traffic on ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) from the internal subnet (e.g., 192.168.1.0/24) to any destination, followed by an implicit deny all rule. This configuration allows only SSH, HTTP, and HTTPS from the internal subnet and drops all other traffic, matching option C.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall allows only loopback traffic.
Why it's wrong here
The exhibit shows rules permitting traffic beyond the loopback interface, so this understates the configuration. It is tempting because loopback-only rules appear on hardened hosts, where a firewall genuinely restricted to 127.0.0.1 traffic would be described this way.
- ✗
The firewall allows all traffic from the internal subnet.
Why it's wrong here
The exhibit's rules restrict traffic to specific ports and sources rather than permitting the whole internal subnet, so this misreads the configuration. It is tempting because permissive internal-to-any rules are common in flat trusted networks, where such a broad allow would genuinely be the described state.
- ✓
The firewall allows SSH, HTTP, and HTTPS from the internal subnet and drops all other traffic.
Why this is correct
The rule set explicitly permits TCP ports 22, 80, and 443 sourced from the internal subnet, satisfying the requirement to allow SSH, HTTP, and HTTPS from that segment. A terminal deny-any rule then discards all remaining traffic, matching the default-deny posture the exhibit demonstrates.
- ✗
The firewall allows all traffic from external sources.
Why it's wrong here
The exhibit's rules do not open the firewall to all external sources; inbound access is limited to named ports or addresses. It is tempting because any any inbound rules are a frequent misconfiguration, so a firewall genuinely permitting unrestricted external traffic would match this description.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.