Egress filtering
Rules at the network edge that limit which traffic may leave, restricting outbound destinations and services and dropping packets whose source address is not the organisation's own.
Egress filtering controls what may leave a network, applied at the edge where the organisation’s network meets others. NIST SP 800-41 Rev 1 describes it alongside ingress filtering. Outbound rules commonly permit only the destinations and services the business needs, so that a compromised host cannot open arbitrary connections to the outside, and they drop packets whose source address does not belong to the organisation. That second rule helps stop the network being used to send traffic with spoofed addresses, the raw material of reflected distributed denial-of-service attacks against others.
The confusion to avoid is between filtering and egress monitoring. Filtering is preventive: it blocks traffic according to rules set in advance. Monitoring is detective: it watches what does leave for signs of exfiltration or command-and-control beacons. They work together, because traffic that fits an allowed rule still needs watching. Egress filtering also limits what malware can reach after it is inside, which is why it counts as a containment control as well as a perimeter one.
Exam relevance: a common trap treats filtering as purely about inbound traffic. A scenario about stopping internal hosts from taking part in spoofed attacks, or narrowing the paths data can take out of the network, is likely to point to egress filtering; one about spotting exfiltration that has already happened points to monitoring.