ISC2 Certified in Cybersecurity (CC) Practice Question
To minimize exposure to network attacks, administrators often apply the principle of least privilege on a perimeter firewall by implementing which default policy before adding specific allow rules?
Allow all traffic originating inside the network by default
Allow traffic from any external host that is on a predefined trusted list by default
Deny all traffic by default and explicitly permit required flows
Deny only UDP traffic while allowing all other protocols by default
A default-deny (or implicit deny) policy means the firewall blocks all traffic unless an explicit rule permits it. This minimizes attack surfaces because unsolicited or misconfigured traffic is discarded automatically. Simply denying only UDP, allowing all internal traffic, or trusting certain external IP ranges by default still leaves unnecessary openings that attackers can exploit. Starting with deny-all and then adding narrowly scoped permit rules best enforces least privilege.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege in cybersecurity?
Open an interactive chat with Bash
How does a perimeter firewall function to secure a network?
Open an interactive chat with Bash
What are the differences between an implicit deny and explicit allow policy?
Open an interactive chat with Bash
ISC2 Certified in Cybersecurity (CC)
Network Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .