CISSP Practice Question: As a security administrator, you are implementing a firewall rule to restrict…
Correct Answer: C. Allow outbound traffic on specific ports based on business requirements
Explanation (CISSP Manager Logic):
This approach applies the principle of least privilege by ensuring only authorized communication necessary for business operations is permitted. Managers must balance security with functionality, explicitly defining allowed services to minimize the attack surface without disrupting critical workflows.
By implementing this solution, you:
- Enforce the principle of least privilege at the network level.
- Reduce the risk of data exfiltration from compromised systems.
- Align technical controls with specific business requirements.
While the other options are relevant, they fall short because:
- A: This is overly permissive and creates an unacceptable level of risk by allowing all potential egress threats.
- B: This creates a self-imposed denial of service that prevents the server from performing its intended business function.
- D: This addresses ingress traffic, failing to meet the specific requirement of controlling outbound communication.
Think like a manager:
Security must support business objectives. Always default to "deny all" and only permit traffic that has a documented business justification.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial