🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company uses a legacy application that performs active FTP transfers to a partner site on the public Internet. The perimeter device is a stateful firewall with no FTP helper or ALG enabled. To keep the application functional while following the principle of least privilege, which pair of TCP rules should you configure on the firewall?

  • Allow outbound TCP from any high client port to destination ports 20 and 21 only; block all inbound traffic from the FTP server.

  • Allow outbound TCP from any high client port to destination port 21, and allow inbound TCP with source port 20 to client high ports; deny all other FTP-related traffic.

  • Allow outbound TCP from any high client port to destination port 21 and allow inbound TCP to destination port 21 from any source; deny all other FTP traffic.

  • Allow outbound TCP from source port 20 to destination port 20 and inbound TCP from source port 21 to destination port 21; deny all others.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot