Which of the following delineates why it is important to perform egress filtering and monitoring on Internet connected security zones of interfaces on a firewall?
A. Egress traffic is more important than ingress traffic for malware prevention
B. To rebalance the amount of outbound traffic and inbound traffic
C. Outbound traffic could be communicating to known botnet sources
D. To prevent DDoS attacks originating from external network
C
i agree with you 100%. but CompTIA wants to make you look at it from a different angle. If traffic outbound does not match with inbound, there is something wrong. I still see it, as foremost, reason for outbound traffic being more to do with botnet sources than anything else