🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security engineer is configuring a host-based firewall on a legacy Windows application server. The service listens on TCP port 135 to negotiate Remote Procedure Call (RPC) sessions, then dynamically opens high-numbered ports for data transfer. The engineer wants to allow the response traffic on these ephemeral ports without broadly exposing them to the network. Which firewall feature is required to meet this goal while still blocking unsolicited inbound connections?

  • Inspecting packet payloads at the application layer for malicious signatures before forwarding

  • Filtering packets solely on fixed source and destination port numbers without tracking session context

  • Maintaining a state table that dynamically allows response packets belonging to an established outbound connection

  • Rewriting internal IP addresses and ports to public ones using network address translation (NAT)

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot