When establishing firewall rules, What is the most prudent configuration?
1) Implicitly deny all traffic by blocking it by default
2) Allow all traffic by default and block specific traffic as needed
3) Create new rules as exceptions based on business need and justification
4) Rely on default firewall rules without making any changes