Your SOC manager wants to reduce the risk of data exfiltration and C2 beaconing by ensuring that internal hosts can only communicate with known, approved external services. Which architectural control best enforces this 'default deny' posture for outbound traffic?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a bouncer at a club: a blocklist checks everyone for trouble, but an allowlist only lets in the people on the list. If you want to stop C2 and exfil by default, you have to block everything except what you explicitly approve. That’s egress filtering with an allowlist. Don't get tricked into thinking monitoring or signature blocking is enough—those are detective or reactive, not preventive by default.
Full Explanation
Egress filtering with an allowlist enforces a default-deny posture for outbound traffic. It permits only explicitly approved destinations, such as vetted cloud endpoints, update servers, or business services. This prevents unknown external systems from receiving data or issuing C2 commands. Because unknown destinations are blocked at the network boundary, the architecture reduces both beaconing and exfiltration risk before monitoring or signature detection is needed. Inline IPS is useful for blocking known malicious traffic, but it depends on current signatures or behavioral rules. It does not by itself deny every unknown destination, so novel or newly registered C2 infrastructure may still pass. Split-tunnel VPNs create a separate path for remote internet access, which can bypass centralized egress controls and expand the exfiltration surface. Full-packet capture gives visibility for forensics and hunting, but it records traffic rather than stopping unauthorized outbound connections. Exam caveat: Do not confuse ingress filtering with egress filtering; the question targets outbound control. Operational check: Review firewall outbound deny logs first, then build the allowlist around confirmed business destinations before enforcing default deny.