SSCP Exam QuestionsBrowse all questions from this exam

SSCP Exam - Question 149


Which of the following packets should NOT be dropped at a firewall protecting an organization's internal network?

Show Answer
Correct Answer: D

Outbound packets with an external destination IP address should not be dropped because they represent normal outbound traffic initiated by internal users trying to reach external resources. Dropping these packets would disrupt the ability of internal network users to access external services, which is typically necessary for normal operations. Conversely, packets with source routing options, router information exchange protocols, and inbound packets with internal source IP addresses could pose security risks or indicate misconfigurations and should generally be dropped.

Discussion

3 comments
Sign in to comment
kmanbOption: C
Jan 12, 2023

Inbound packets with an internal address as the source IP address. These packets are likely to be generated by internal hosts, and their traffic needs to be allowed to reach other internal hosts and systems. Blocking this traffic would disrupt normal network communications and potentially prevent internal hosts from functioning properly.

bradseth
Feb 3, 2023

chatgpt again?

CraigB83Option: D
Nov 28, 2023

why would an internal host need to route via the firewall? C is not correct.

gabbinuOption: D
May 14, 2024

Correct answer is D without doubt