CertNova
Menu
← Back to PBQ types

Firewall PBQs: CompTIA SecurityX (CAS-005)

easy

Question 1 of 3

Your organization's DMZ web server (10.1.0.0/24) currently accepts both HTTP and HTTPS from the internet. A new security policy requires all public web traffic to use HTTPS only, and HTTP must be blocked. Additionally, SSH access to the DMZ is wide open and must be restricted to the management subnet (10.2.0.0/24). Review the firewall rules and correct them to comply with the updated policy.

Firewall Rules

#DirectionSourcePortProtocolActionOrder
1inboundany80tcpallow
2inboundany443tcpallow
3inboundany22tcpallow
4inboundanyanyanydeny

Rules are evaluated top to bottom. Use ▲▼ to reorder.

Progress

0 of 3 rules correct

Edit or add rules to configure the firewall, then mark complete

0 of 3 marked complete