GIAC Security Essentials Certification (GSEC) — Question 36
When considering ingress filtering, why should all inbound packets be dropped if they contain a source address from within the protected network address space?
Answer options
- A. A and B
- B. B and C
- C. B and D
- D. A and D
Correct answer: B
Explanation
The correct answer is B because allowing packets with internal source addresses could indicate a spoofing attack, which compromises network security. Options A, C, and D include incorrect combinations, as they do not accurately address the reasoning behind the filtering process.