CompTIA Security+ SY0-701 Securing Enterprise Infrastructure Practice Test
Topic 11 focuses on Securing Enterprise Infrastructure for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
What is a logical or physical area containing systems with similar trust or security requirements?
Correct Answer: A
Correct Answer
Answer A is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements.
Incorrect Answers
Answer B is incorrect because Unified threat management (UTM) represents a different security function. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.
Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer D is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Question 2
To decrease the number of opportunities available to an attacker, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Incorrect Answers
Answer B is incorrect because Inline security device addresses a different security requirement. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.
Answer C is incorrect because 802.1X addresses a different requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Answer D is incorrect because Tap or monitor deployment would fit a different scenario. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Question 3
What is a failure mode in which access or traffic is allowed when a security control fails?
Correct Answer: C
Correct Answer
Answer C is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails.
Incorrect Answers
Answer A is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer B is incorrect because Extensible Authentication Protocol (EAP) would fit a different scenario. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer D is incorrect because Secure access service edge (SASE) represents a different security function. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.
Question 4
To preserve security even if a control malfunction interrupts service, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer B is incorrect because 802.1X addresses a different security requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Answer C is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.
Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Question 5
What is a device placed directly in the traffic path so it can actively allow, block, or modify flows?
Correct Answer: A
Correct Answer
Answer A is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows.
Incorrect Answers
Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer C is incorrect because Tap or monitor deployment would fit a different scenario. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Answer D is incorrect because Next-generation firewall (NGFW) addresses a different requirement. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.
Question 6
To inspect traffic with minimal risk of interrupting network flow, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Incorrect Answers
Answer B is incorrect because Intrusion prevention system (IPS) addresses a different security requirement. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.
Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer D is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Question 7
Which hardened intermediary host is used as a controlled administrative entry point to protected systems?
Correct Answer: B
Correct Answer
Answer B is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems.
Incorrect Answers
Answer A is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer C is incorrect because TLS tunnel addresses a different requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Answer D is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.
Question 8
To control and observe application access between clients and destinations, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer B is incorrect because Layer 7 firewalling addresses a different requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.
Answer C is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Question 9
Which security system identifies suspicious activity and produces alerts but typically does not block traffic directly?
Correct Answer: A
Correct Answer
Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.
Incorrect Answers
Answer B is incorrect because Unified threat management (UTM) would fit a different scenario. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.
Answer C is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Question 10
To stop known or suspected attacks in the network path, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic.
Incorrect Answers
Answer A is incorrect because Next-generation firewall (NGFW) would fit a different scenario. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.
Answer B is incorrect because Jump server addresses a different requirement. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.
Answer C is incorrect because Virtual private network (VPN) addresses a different security requirement. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.
Question 11
Which system distributes client requests across multiple backend resources?
Correct Answer: A
Correct Answer
Answer A is correct because Load balancer means a system that distributes client requests across multiple backend resources.
Incorrect Answers
Answer B is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer C is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer D is incorrect because Fail-open design represents a different security function. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.
Question 12
To require identity-based authorization before granting normal wired or wireless network access, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Incorrect Answers
Answer A is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Answer B is incorrect because Layer 4 firewalling addresses a different requirement. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Question 13
Which framework supports multiple authentication methods and is commonly used with 802.1X?
Correct Answer: C
Correct Answer
Answer C is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X.
Incorrect Answers
Answer A is incorrect because Secure access service edge (SASE) addresses a different requirement. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.
Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer D is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Question 14
To protect web applications from malicious requests such as injection and protocol abuse, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Incorrect Answers
Answer A is incorrect because Proxy server addresses a different security requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer B is incorrect because Virtual private network (VPN) would fit a different scenario. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.
Answer D is incorrect because IPsec tunnel addresses a different requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Question 15
Which security appliance combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention?
Correct Answer: B
Correct Answer
Answer B is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.
Incorrect Answers
Answer A is incorrect because 802.1X addresses a different requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Answer C is incorrect because Jump server represents a different security function. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.
Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Question 16
To enforce policy using deeper context than addresses and ports alone, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features.
Incorrect Answers
Answer A is incorrect because IPsec tunnel addresses a different security requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer C is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer D is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.
Question 17
Which term describes traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state?
Correct Answer: C
Correct Answer
Answer C is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Incorrect Answers
Answer A is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer B is incorrect because Jump server would fit a different scenario. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.
Answer D is incorrect because Extensible Authentication Protocol (EAP) represents a different security function. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Question 18
To apply policy based on application behavior, commands, users, or content, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content.
Incorrect Answers
Answer A is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Answer C is incorrect because Attack-surface reduction addresses a different security requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Question 19
What is an encrypted logical connection across an untrusted network?
Correct Answer: D
Correct Answer
Answer D is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network.
Incorrect Answers
Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer B is incorrect because Attack-surface reduction represents a different security function. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer C is incorrect because Unified threat management (UTM) addresses a different requirement. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.
Question 20
To secure client-server application traffic such as HTTPS, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication.
Incorrect Answers
Answer A is incorrect because Secure access service edge (SASE) addresses a different requirement. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.
Answer C is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer D is incorrect because Extensible Authentication Protocol (EAP) addresses a different security requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Question 21
What is a suite of network-layer protocols used to authenticate and encrypt IP traffic?
Correct Answer: D
Correct Answer
Answer D is correct because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Incorrect Answers
Answer A is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer B is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer C is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Question 22
To optimize and control branch connectivity while applying centralized policy, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.
Incorrect Answers
Answer A is incorrect because 802.1X addresses a different security requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer D is incorrect because Inline security device would fit a different scenario. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.
Question 23
What is a cloud-delivered architecture combining networking and security capabilities near users and applications?
Correct Answer: D
Correct Answer
Answer D is correct because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications.
Incorrect Answers
Answer A is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Answer B is incorrect because Layer 7 firewalling represents a different security function. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.
Answer C is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Question 24
To apply consistent controls between groups of assets with different risk levels, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements.
Incorrect Answers
Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer B is incorrect because TLS tunnel represents a different security function. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Answer D is incorrect because Jump server addresses a different requirement. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.
Question 25
Which term describes removal or restriction of unnecessary reachable services, interfaces, paths, or functionality?
Correct Answer: A
Correct Answer
Answer A is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Incorrect Answers
Answer B is incorrect because Extensible Authentication Protocol (EAP) addresses a different security requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer C is incorrect because IPsec tunnel addresses a different requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer D is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.
Question 26
To preserve availability when interruption is considered more harmful than reduced enforcement, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails.
Incorrect Answers
Answer A is incorrect because Secure access service edge (SASE) would fit a different scenario. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.
Answer B is incorrect because Virtual private network (VPN) addresses a different requirement. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.
Answer D is incorrect because Tap or monitor deployment represents a different security function. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Question 27
What is a failure mode in which access or traffic is blocked when a security control fails?
Correct Answer: B
Correct Answer
Answer B is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer A is incorrect because IPsec tunnel addresses a different security requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer C is incorrect because SD-WAN addresses a different requirement. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.
Answer D is incorrect because Secure access service edge (SASE) would fit a different scenario. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.
Question 28
To enforce security decisions on live traffic, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows.
Incorrect Answers
Answer A is incorrect because Fail-open design represents a different security function. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.
Answer B is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer D is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Question 29
Which passive observation design receives copies of traffic without sitting directly in the forwarding path?
Correct Answer: B
Correct Answer
Answer B is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Incorrect Answers
Answer A is incorrect because Next-generation firewall (NGFW) addresses a different security requirement. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.
Answer C is incorrect because Layer 7 firewalling would fit a different scenario. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.
Answer D is incorrect because Inline security device addresses a different requirement. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.
Question 30
To centralize and monitor privileged remote management access, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems.
Incorrect Answers
Answer A is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer C is incorrect because TLS tunnel would fit a different scenario. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Question 31
Which intermediary makes requests on behalf of clients and can enforce policy, filtering, or inspection?
Correct Answer: B
Correct Answer
Answer B is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer A is incorrect because Layer 4 firewalling addresses a different requirement. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Answer C is incorrect because Tap or monitor deployment addresses a different security requirement. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Answer D is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Question 32
To detect likely attacks while operating passively or out of band, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.
Incorrect Answers
Answer B is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer C is incorrect because Fail-open design addresses a different requirement. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.
Answer D is incorrect because Tap or monitor deployment represents a different security function. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Question 33
What is a security system positioned to detect and actively block suspicious traffic?
Correct Answer: D
Correct Answer
Answer D is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic.
Incorrect Answers
Answer A is incorrect because Layer 4 firewalling would fit a different scenario. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Answer B is incorrect because Layer 7 firewalling addresses a different security requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.
Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Question 34
To improve availability, capacity, and sometimes security by controlling service distribution, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Load balancer means a system that distributes client requests across multiple backend resources.
Incorrect Answers
Answer A is incorrect because Fail-closed design represents a different security function. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Answer B is incorrect because SD-WAN would fit a different scenario. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.
Answer C is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Question 35
What is a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server?
Correct Answer: D
Correct Answer
Answer D is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Incorrect Answers
Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Answer B is incorrect because Security zone addresses a different security requirement. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.
Answer C is incorrect because Layer 7 firewalling addresses a different requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.
Question 36
To carry authentication exchanges for enterprise network access, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X.
Incorrect Answers
Answer A is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer B is incorrect because Fail-closed design addresses a different requirement. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Answer D is incorrect because 802.1X represents a different security function. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Question 37
What is a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic?
Correct Answer: C
Correct Answer
Answer C is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Incorrect Answers
Answer A is incorrect because Load balancer addresses a different requirement. Load balancer refers to a system that distributes client requests across multiple backend resources.
Answer B is incorrect because Fail-open design would fit a different scenario. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.
Answer D is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.
Question 38
To consolidate multiple security controls into one managed platform, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.
Incorrect Answers
Answer A is incorrect because Layer 4 firewalling represents a different security function. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Answer B is incorrect because Intrusion detection system (IDS) addresses a different requirement. Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.
Answer C is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.
Question 39
Which firewall combines stateful filtering with application awareness and advanced inspection features?
Correct Answer: D
Correct Answer
Answer D is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features.
Incorrect Answers
Answer A is incorrect because Fail-closed design addresses a different security requirement. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.
Answer B is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Answer C is incorrect because Extensible Authentication Protocol (EAP) would fit a different scenario. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.
Question 40
To control flows based on network and transport characteristics, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Incorrect Answers
Answer A is incorrect because Intrusion detection system (IDS) addresses a different requirement. Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.
Answer C is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.
Answer D is incorrect because SD-WAN represents a different security function. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.
Popular posts
Recent Posts
