Suggested Answer: D
Explanation:
A host-based firewall controls network connections to and from an individual endpoint or server. Its primary purpose is to prevent unauthorized or suspicious network connections by enforcing local rules based on ports, protocols, applications, network profiles, or direction of traffic. For example, it can block inbound connections to services that should not be exposed or restrict outbound traffic from suspicious applications. Exhaustion of network memory resources describes a denial-of-service concern, not the normal role of a host firewall. Privilege escalation is an endpoint attack technique, but it is usually addressed through patching, least privilege, exploit prevention, and operating system hardening rather than host firewall rules alone. Pop-up advertisements are typically handled by browser controls or anti-adware functions. Host-based firewalls are valuable because they continue to enforce policy even when the device moves between networks, such as home, office, and public Wi-Fi. Reference/topics: Endpoint Security 4.3, host-based firewalls; Endpoint Security 4.2, endpoint security objectives.