ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During final hardening of a new Linux server that will expose a single REST API on TCP port 8443, you decide to enable the host-based firewall even though an external network firewall already restricts traffic. Which host firewall rule set best supports a defense-in-depth strategy while enforcing a default-deny posture without disrupting the application's operation?

  • Set default DROP on INPUT and OUTPUT; allow inbound TCP 8443 from required sources; allow only RELATED and ESTABLISHED outbound traffic.

  • Set default ACCEPT on OUTPUT; set default DROP on INPUT but allow inbound TCP 8443 and SSH from any host.

  • Leave default ACCEPT on all chains; simply log all packets for audit purposes.

  • Disable the host-based firewall and rely on the network firewall, since it already permits only TCP 8443 inbound.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot