CompTIA Security+ SY0-701 Securing Enterprise Infrastructure Practice Test

 

Topic 11 focuses on Securing Enterprise Infrastructure for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is a logical or physical area containing systems with similar trust or security requirements?

  1. Security zone
  2. Unified threat management (UTM)
  3. Extensible Authentication Protocol (EAP)
  4. Web application firewall (WAF)

Correct Answer: A

 

Correct Answer

Answer A is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements.

Incorrect Answers

Answer B is incorrect because Unified threat management (UTM) represents a different security function. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.

Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer D is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

 

Question 2

To decrease the number of opportunities available to an attacker, which security approach should be selected?

  1. Attack-surface reduction
  2. Inline security device
  3. 802.1X
  4. Tap or monitor deployment

Correct Answer: A

 

Correct Answer

Answer A is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Incorrect Answers

Answer B is incorrect because Inline security device addresses a different security requirement. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.

Answer C is incorrect because 802.1X addresses a different requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Answer D is incorrect because Tap or monitor deployment would fit a different scenario. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

 

Question 3

What is a failure mode in which access or traffic is allowed when a security control fails?

  1. Attack-surface reduction
  2. Extensible Authentication Protocol (EAP)
  3. Fail-open design
  4. Secure access service edge (SASE)

Correct Answer: C

 

Correct Answer

Answer C is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails.

Incorrect Answers

Answer A is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer B is incorrect because Extensible Authentication Protocol (EAP) would fit a different scenario. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer D is incorrect because Secure access service edge (SASE) represents a different security function. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.

 

Question 4

To preserve security even if a control malfunction interrupts service, which security approach should be selected?

  1. Fail-closed design
  2. 802.1X
  3. Load balancer
  4. Web application firewall (WAF)

Correct Answer: A

 

Correct Answer

Answer A is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails.

Incorrect Answers

Answer B is incorrect because 802.1X addresses a different security requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Answer C is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.

Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

 

Question 5

What is a device placed directly in the traffic path so it can actively allow, block, or modify flows?

  1. Inline security device
  2. Security zone
  3. Tap or monitor deployment
  4. Next-generation firewall (NGFW)

Correct Answer: A

 

Correct Answer

Answer A is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows.

Incorrect Answers

Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer C is incorrect because Tap or monitor deployment would fit a different scenario. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

Answer D is incorrect because Next-generation firewall (NGFW) addresses a different requirement. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.

 

Question 6

To inspect traffic with minimal risk of interrupting network flow, which security approach should be selected?

  1. Tap or monitor deployment
  2. Intrusion prevention system (IPS)
  3. Extensible Authentication Protocol (EAP)
  4. Attack-surface reduction

Correct Answer: A

 

Correct Answer

Answer A is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

Incorrect Answers

Answer B is incorrect because Intrusion prevention system (IPS) addresses a different security requirement. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.

Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer D is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

 

Question 7

Which hardened intermediary host is used as a controlled administrative entry point to protected systems?

  1. Security zone
  2. Jump server
  3. TLS tunnel
  4. Load balancer

Correct Answer: B

 

Correct Answer

Answer B is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems.

Incorrect Answers

Answer A is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer C is incorrect because TLS tunnel addresses a different requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

Answer D is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.

 

Question 8

To control and observe application access between clients and destinations, which security approach should be selected?

  1. Proxy server
  2. Layer 7 firewalling
  3. TLS tunnel
  4. Fail-closed design

Correct Answer: A

 

Correct Answer

Answer A is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Incorrect Answers

Answer B is incorrect because Layer 7 firewalling addresses a different requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.

Answer C is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

 

Question 9

Which security system identifies suspicious activity and produces alerts but typically does not block traffic directly?

  1. Intrusion detection system (IDS)
  2. Unified threat management (UTM)
  3. Security zone
  4. Web application firewall (WAF)

Correct Answer: A

 

Correct Answer

Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.

Incorrect Answers

Answer B is incorrect because Unified threat management (UTM) would fit a different scenario. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.

Answer C is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

 

Question 10

To stop known or suspected attacks in the network path, which security approach should be selected?

  1. Next-generation firewall (NGFW)
  2. Jump server
  3. Virtual private network (VPN)
  4. Intrusion prevention system (IPS)

Correct Answer: D

 

Correct Answer

Answer D is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic.

Incorrect Answers

Answer A is incorrect because Next-generation firewall (NGFW) would fit a different scenario. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.

Answer B is incorrect because Jump server addresses a different requirement. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.

Answer C is incorrect because Virtual private network (VPN) addresses a different security requirement. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.

 

Question 11

Which system distributes client requests across multiple backend resources?

  1. Load balancer
  2. Extensible Authentication Protocol (EAP)
  3. Attack-surface reduction
  4. Fail-open design

Correct Answer: A

 

Correct Answer

Answer A is correct because Load balancer means a system that distributes client requests across multiple backend resources.

Incorrect Answers

Answer B is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer C is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer D is incorrect because Fail-open design represents a different security function. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.

 

Question 12

To require identity-based authorization before granting normal wired or wireless network access, which security approach should be selected?

  1. TLS tunnel
  2. Layer 4 firewalling
  3. 802.1X
  4. Fail-closed design

Correct Answer: C

 

Correct Answer

Answer C is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Incorrect Answers

Answer A is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

Answer B is incorrect because Layer 4 firewalling addresses a different requirement. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

 

Question 13

Which framework supports multiple authentication methods and is commonly used with 802.1X?

  1. Secure access service edge (SASE)
  2. Security zone
  3. Extensible Authentication Protocol (EAP)
  4. Proxy server

Correct Answer: C

 

Correct Answer

Answer C is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X.

Incorrect Answers

Answer A is incorrect because Secure access service edge (SASE) addresses a different requirement. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.

Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer D is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

 

Question 14

To protect web applications from malicious requests such as injection and protocol abuse, which security approach should be selected?

  1. Proxy server
  2. Virtual private network (VPN)
  3. Web application firewall (WAF)
  4. IPsec tunnel

Correct Answer: C

 

Correct Answer

Answer C is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

Incorrect Answers

Answer A is incorrect because Proxy server addresses a different security requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer B is incorrect because Virtual private network (VPN) would fit a different scenario. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.

Answer D is incorrect because IPsec tunnel addresses a different requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

 

Question 15

Which security appliance combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention?

  1. 802.1X
  2. Unified threat management (UTM)
  3. Jump server
  4. Fail-closed design

Correct Answer: B

 

Correct Answer

Answer B is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.

Incorrect Answers

Answer A is incorrect because 802.1X addresses a different requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Answer C is incorrect because Jump server represents a different security function. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.

Answer D is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

 

Question 16

To enforce policy using deeper context than addresses and ports alone, which security approach should be selected?

  1. IPsec tunnel
  2. Next-generation firewall (NGFW)
  3. Proxy server
  4. Load balancer

Correct Answer: B

 

Correct Answer

Answer B is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features.

Incorrect Answers

Answer A is incorrect because IPsec tunnel addresses a different security requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer C is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer D is incorrect because Load balancer would fit a different scenario. Load balancer refers to a system that distributes client requests across multiple backend resources.

 

Question 17

Which term describes traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state?

  1. Proxy server
  2. Jump server
  3. Layer 4 firewalling
  4. Extensible Authentication Protocol (EAP)

Correct Answer: C

 

Correct Answer

Answer C is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Incorrect Answers

Answer A is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer B is incorrect because Jump server would fit a different scenario. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.

Answer D is incorrect because Extensible Authentication Protocol (EAP) represents a different security function. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

 

Question 18

To apply policy based on application behavior, commands, users, or content, which security approach should be selected?

  1. Fail-closed design
  2. Layer 7 firewalling
  3. Attack-surface reduction
  4. Web application firewall (WAF)

Correct Answer: B

 

Correct Answer

Answer B is correct because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content.

Incorrect Answers

Answer A is incorrect because Fail-closed design would fit a different scenario. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

Answer C is incorrect because Attack-surface reduction addresses a different security requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer D is incorrect because Web application firewall (WAF) addresses a different requirement. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

 

Question 19

What is an encrypted logical connection across an untrusted network?

  1. IPsec tunnel
  2. Attack-surface reduction
  3. Unified threat management (UTM)
  4. Virtual private network (VPN)

Correct Answer: D

 

Correct Answer

Answer D is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network.

Incorrect Answers

Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer B is incorrect because Attack-surface reduction represents a different security function. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer C is incorrect because Unified threat management (UTM) addresses a different requirement. Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.

 

Question 20

To secure client-server application traffic such as HTTPS, which security approach should be selected?

  1. Secure access service edge (SASE)
  2. TLS tunnel
  3. Proxy server
  4. Extensible Authentication Protocol (EAP)

Correct Answer: B

 

Correct Answer

Answer B is correct because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication.

Incorrect Answers

Answer A is incorrect because Secure access service edge (SASE) addresses a different requirement. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.

Answer C is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer D is incorrect because Extensible Authentication Protocol (EAP) addresses a different security requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

 

Question 21

What is a suite of network-layer protocols used to authenticate and encrypt IP traffic?

  1. Attack-surface reduction
  2. Proxy server
  3. Security zone
  4. IPsec tunnel

Correct Answer: D

 

Correct Answer

Answer D is correct because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Incorrect Answers

Answer A is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer B is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer C is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

 

Question 22

To optimize and control branch connectivity while applying centralized policy, which security approach should be selected?

  1. 802.1X
  2. SD-WAN
  3. Extensible Authentication Protocol (EAP)
  4. Inline security device

Correct Answer: B

 

Correct Answer

Answer B is correct because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.

Incorrect Answers

Answer A is incorrect because 802.1X addresses a different security requirement. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer D is incorrect because Inline security device would fit a different scenario. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.

 

Question 23

What is a cloud-delivered architecture combining networking and security capabilities near users and applications?

  1. Web application firewall (WAF)
  2. Layer 7 firewalling
  3. Proxy server
  4. Secure access service edge (SASE)

Correct Answer: D

 

Correct Answer

Answer D is correct because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications.

Incorrect Answers

Answer A is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

Answer B is incorrect because Layer 7 firewalling represents a different security function. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.

Answer C is incorrect because Proxy server addresses a different requirement. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

 

Question 24

To apply consistent controls between groups of assets with different risk levels, which security approach should be selected?

  1. IPsec tunnel
  2. TLS tunnel
  3. Security zone
  4. Jump server

Correct Answer: C

 

Correct Answer

Answer C is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements.

Incorrect Answers

Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer B is incorrect because TLS tunnel represents a different security function. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

Answer D is incorrect because Jump server addresses a different requirement. Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems.

 

Question 25

Which term describes removal or restriction of unnecessary reachable services, interfaces, paths, or functionality?

  1. Attack-surface reduction
  2. Extensible Authentication Protocol (EAP)
  3. IPsec tunnel
  4. Intrusion prevention system (IPS)

Correct Answer: A

 

Correct Answer

Answer A is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Incorrect Answers

Answer B is incorrect because Extensible Authentication Protocol (EAP) addresses a different security requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer C is incorrect because IPsec tunnel addresses a different requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer D is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.

 

Question 26

To preserve availability when interruption is considered more harmful than reduced enforcement, which security approach should be selected?

  1. Secure access service edge (SASE)
  2. Virtual private network (VPN)
  3. Fail-open design
  4. Tap or monitor deployment

Correct Answer: C

 

Correct Answer

Answer C is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails.

Incorrect Answers

Answer A is incorrect because Secure access service edge (SASE) would fit a different scenario. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.

Answer B is incorrect because Virtual private network (VPN) addresses a different requirement. Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network.

Answer D is incorrect because Tap or monitor deployment represents a different security function. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

 

Question 27

What is a failure mode in which access or traffic is blocked when a security control fails?

  1. IPsec tunnel
  2. Fail-closed design
  3. SD-WAN
  4. Secure access service edge (SASE)

Correct Answer: B

 

Correct Answer

Answer B is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails.

Incorrect Answers

Answer A is incorrect because IPsec tunnel addresses a different security requirement. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer C is incorrect because SD-WAN addresses a different requirement. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.

Answer D is incorrect because Secure access service edge (SASE) would fit a different scenario. Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications.

 

Question 28

To enforce security decisions on live traffic, which security approach should be selected?

  1. Fail-open design
  2. Attack-surface reduction
  3. Inline security device
  4. Web application firewall (WAF)

Correct Answer: C

 

Correct Answer

Answer C is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows.

Incorrect Answers

Answer A is incorrect because Fail-open design represents a different security function. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.

Answer B is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer D is incorrect because Web application firewall (WAF) would fit a different scenario. Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

 

Question 29

Which passive observation design receives copies of traffic without sitting directly in the forwarding path?

  1. Next-generation firewall (NGFW)
  2. Tap or monitor deployment
  3. Layer 7 firewalling
  4. Inline security device

Correct Answer: B

 

Correct Answer

Answer B is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

Incorrect Answers

Answer A is incorrect because Next-generation firewall (NGFW) addresses a different security requirement. Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features.

Answer C is incorrect because Layer 7 firewalling would fit a different scenario. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.

Answer D is incorrect because Inline security device addresses a different requirement. Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows.

 

Question 30

To centralize and monitor privileged remote management access, which security approach should be selected?

  1. Extensible Authentication Protocol (EAP)
  2. Security zone
  3. TLS tunnel
  4. Jump server

Correct Answer: D

 

Correct Answer

Answer D is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems.

Incorrect Answers

Answer A is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

Answer B is incorrect because Security zone represents a different security function. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer C is incorrect because TLS tunnel would fit a different scenario. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

 

Question 31

Which intermediary makes requests on behalf of clients and can enforce policy, filtering, or inspection?

  1. Layer 4 firewalling
  2. Proxy server
  3. Tap or monitor deployment
  4. Attack-surface reduction

Correct Answer: B

 

Correct Answer

Answer B is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Incorrect Answers

Answer A is incorrect because Layer 4 firewalling addresses a different requirement. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Answer C is incorrect because Tap or monitor deployment addresses a different security requirement. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

Answer D is incorrect because Attack-surface reduction would fit a different scenario. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

 

Question 32

To detect likely attacks while operating passively or out of band, which security approach should be selected?

  1. Intrusion detection system (IDS)
  2. IPsec tunnel
  3. Fail-open design
  4. Tap or monitor deployment

Correct Answer: A

 

Correct Answer

Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.

Incorrect Answers

Answer B is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer C is incorrect because Fail-open design addresses a different requirement. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.

Answer D is incorrect because Tap or monitor deployment represents a different security function. Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path.

 

Question 33

What is a security system positioned to detect and actively block suspicious traffic?

  1. Layer 4 firewalling
  2. Layer 7 firewalling
  3. Extensible Authentication Protocol (EAP)
  4. Intrusion prevention system (IPS)

Correct Answer: D

 

Correct Answer

Answer D is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic.

Incorrect Answers

Answer A is incorrect because Layer 4 firewalling would fit a different scenario. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Answer B is incorrect because Layer 7 firewalling addresses a different security requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.

Answer C is incorrect because Extensible Authentication Protocol (EAP) addresses a different requirement. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

 

Question 34

To improve availability, capacity, and sometimes security by controlling service distribution, which security approach should be selected?

  1. Fail-closed design
  2. SD-WAN
  3. Attack-surface reduction
  4. Load balancer

Correct Answer: D

 

Correct Answer

Answer D is correct because Load balancer means a system that distributes client requests across multiple backend resources.

Incorrect Answers

Answer A is incorrect because Fail-closed design represents a different security function. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

Answer B is incorrect because SD-WAN would fit a different scenario. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.

Answer C is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

 

Question 35

What is a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server?

  1. IPsec tunnel
  2. Security zone
  3. Layer 7 firewalling
  4. 802.1X

Correct Answer: D

 

Correct Answer

Answer D is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

Incorrect Answers

Answer A is incorrect because IPsec tunnel would fit a different scenario. IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic.

Answer B is incorrect because Security zone addresses a different security requirement. Security zone refers to a logical or physical area containing systems with similar trust or security requirements.

Answer C is incorrect because Layer 7 firewalling addresses a different requirement. Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content.

 

Question 36

To carry authentication exchanges for enterprise network access, which security approach should be selected?

  1. Proxy server
  2. Fail-closed design
  3. Extensible Authentication Protocol (EAP)
  4. 802.1X

Correct Answer: C

 

Correct Answer

Answer C is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X.

Incorrect Answers

Answer A is incorrect because Proxy server would fit a different scenario. Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.

Answer B is incorrect because Fail-closed design addresses a different requirement. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

Answer D is incorrect because 802.1X represents a different security function. 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.

 

Question 37

What is a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic?

  1. Load balancer
  2. Fail-open design
  3. Web application firewall (WAF)
  4. TLS tunnel

Correct Answer: C

 

Correct Answer

Answer C is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.

Incorrect Answers

Answer A is incorrect because Load balancer addresses a different requirement. Load balancer refers to a system that distributes client requests across multiple backend resources.

Answer B is incorrect because Fail-open design would fit a different scenario. Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails.

Answer D is incorrect because TLS tunnel addresses a different security requirement. TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication.

 

Question 38

To consolidate multiple security controls into one managed platform, which security approach should be selected?

  1. Layer 4 firewalling
  2. Intrusion detection system (IDS)
  3. Intrusion prevention system (IPS)
  4. Unified threat management (UTM)

Correct Answer: D

 

Correct Answer

Answer D is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention.

Incorrect Answers

Answer A is incorrect because Layer 4 firewalling represents a different security function. Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Answer B is incorrect because Intrusion detection system (IDS) addresses a different requirement. Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.

Answer C is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.

 

Question 39

Which firewall combines stateful filtering with application awareness and advanced inspection features?

  1. Fail-closed design
  2. Attack-surface reduction
  3. Extensible Authentication Protocol (EAP)
  4. Next-generation firewall (NGFW)

Correct Answer: D

 

Correct Answer

Answer D is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features.

Incorrect Answers

Answer A is incorrect because Fail-closed design addresses a different security requirement. Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails.

Answer B is incorrect because Attack-surface reduction addresses a different requirement. Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.

Answer C is incorrect because Extensible Authentication Protocol (EAP) would fit a different scenario. Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X.

 

Question 40

To control flows based on network and transport characteristics, which security approach should be selected?

  1. Intrusion detection system (IDS)
  2. Layer 4 firewalling
  3. Intrusion prevention system (IPS)
  4. SD-WAN

Correct Answer: B

 

Correct Answer

Answer B is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.

Incorrect Answers

Answer A is incorrect because Intrusion detection system (IDS) addresses a different requirement. Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly.

Answer C is incorrect because Intrusion prevention system (IPS) would fit a different scenario. Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic.

Answer D is incorrect because SD-WAN represents a different security function. SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.

img