CertNova
Menu
← Back to PBQ types

Firewall PBQs: CompTIA Cyber Security Analyst (CS0-003)

easy

Question 1 of 3

Your SOC has detected a brute-force attack against SSH and RDP from IP address 203.0.113.50. As part of your incident response, update the firewall to block all traffic from the attacker's IP, restrict SSH access to the admin subnet only, and remove unnecessary RDP exposure. HTTPS must remain accessible to all.

Firewall Rules

#DirectionSourcePortProtocolActionOrder
1inboundany22tcpallow
2inboundany3389tcpallow
3inboundany443tcpallow
4inboundanyanyanydeny

Rules are evaluated top to bottom. Use ▲▼ to reorder.

Progress

0 of 4 rules correct

Edit or add rules to configure the firewall, then mark complete

0 of 3 marked complete