Topic 11 Practice Test 2 covers Securing Enterprise Infrastructure for CompTIA Security+ SY0-701 and maps to objective 3.2: Given a scenario, apply security principles to secure enterprise infrastructure. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
What is a security system positioned to detect and actively block suspicious traffic?
- Layer 7 firewalling
- Extensible Authentication Protocol (EAP)
- Intrusion prevention system (IPS)
- Layer 4 firewalling
Correct Answer: C
Correct Answer
Answer C is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic. That makes it the best answer here; Extensible Authentication Protocol (EAP) addresses a framework that supports multiple authentication methods and is commonly used with 802.1X, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content. The key mismatch is functional: Intrusion prevention system (IPS) addresses a security system positioned to detect and actively block suspicious traffic, the need stated by the question.
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. That concept can be valid in another scenario, but this question is testing a security system positioned to detect and actively block suspicious traffic; Intrusion prevention system (IPS) therefore fits the requirement more directly.
Answer D is incorrect because Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. The key mismatch is functional: Intrusion prevention system (IPS) addresses a security system positioned to detect and actively block suspicious traffic, the need stated by the question.
Question 2
To secure client-server application traffic such as HTTPS, which security approach should be selected?
- Extensible Authentication Protocol (EAP)
- Proxy server
- TLS tunnel
- Secure access service edge (SASE)
Correct Answer: C
Correct Answer
Answer C is correct because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication. This matches the requirement as written. Proxy server can be valid in another context, but it is used for an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer A is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The concept is valid, but it does not match this stem. The required function is encrypted transport using Transport Layer Security to protect application communication, which maps to TLS tunnel.
Answer B is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. This could be appropriate elsewhere, but the required function is encrypted transport using Transport Layer Security to protect application communication; that makes TLS tunnel the precise choice.
Answer D is incorrect because Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications. The scenario instead requires encrypted transport using Transport Layer Security to protect application communication, which is why TLS tunnel is the better answer; this option serves the different function defined above.
Question 3
To stop known or suspected attacks in the network path, which security approach should be selected?
- Jump server
- Next-generation firewall (NGFW)
- Intrusion prevention system (IPS)
- Virtual private network (VPN)
Correct Answer: C
Correct Answer
Answer C is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic. That is the function the question is testing. Virtual private network (VPN) would instead be used for an encrypted logical connection across an untrusted network.
Incorrect Answers
Answer A is incorrect because Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems. The question is not asking for this function. It is testing a security system positioned to detect and actively block suspicious traffic, so Intrusion prevention system (IPS) is the stronger fit.
Answer B is incorrect because Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features. This could be appropriate elsewhere, but the required function is a security system positioned to detect and actively block suspicious traffic; that makes Intrusion prevention system (IPS) the precise choice.
Answer D is incorrect because Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network. That concept can be valid in another scenario, but this question is testing a security system positioned to detect and actively block suspicious traffic; Intrusion prevention system (IPS) therefore fits the requirement more directly.
Question 4
An architect working on an enterprise network-security design review needs one capability that provides logical or physical area containing systems with similar trust or security requirements and another that provides hardened intermediary host used as a controlled administrative entry point to protected systems. Which TWO selections are the best match? Choose TWO.
- 802.1X
- Layer 4 firewalling
- Load balancer
- Jump server
- Security zone
Correct Answers: D, E
Correct Answers
Answer D is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. This selection maps directly to one of the named needs. 802.1X addresses a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server, so it does not satisfy the same slot.
Answer E is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements. It belongs in the fixed-count answer set because it covers one of the stated requirements. 802.1X instead serves a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server and cannot replace this function.
Incorrect Answers
Answer A is incorrect because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. The question requires exactly 2 selections: Security zone, Jump server. This option falls outside that required set.
Answer B is incorrect because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. Every answer slot must map to a stated requirement. The correct set is Security zone, Jump server, so this option cannot replace one of those selections.
Answer C is incorrect because Load balancer means a system that distributes client requests across multiple backend resources. The fixed-count answer set is Security zone, Jump server; this option does not fill one of those named functions. For example, Jump server is required for a hardened intermediary host used as a controlled administrative entry point to protected systems.
Question 5
Which security system identifies suspicious activity and produces alerts but typically does not block traffic directly?
- Security zone
- Intrusion detection system (IDS)
- Web application firewall (WAF)
- Unified threat management (UTM)
Correct Answer: B
Correct Answer
Answer B is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. The deciding point is functional fit: this option covers the stated need, while Security zone addresses a logical or physical area containing systems with similar trust or security requirements.
Incorrect Answers
Answer A is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. The scenario instead requires a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly, which is why Intrusion detection system (IDS) is the better answer; this option serves the different function defined above.
Answer C is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The concept is valid, but it does not match this stem. The required function is a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly, which maps to Intrusion detection system (IDS).
Answer D is incorrect because Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The question is not asking for this function. It is testing a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly, so Intrusion detection system (IDS) is the stronger fit.
Question 6
Which system distributes client requests across multiple backend resources?
- Attack-surface reduction
- Extensible Authentication Protocol (EAP)
- Load balancer
- Fail-open design
Correct Answer: C
Correct Answer
Answer C is correct because Load balancer means a system that distributes client requests across multiple backend resources. The requirement maps directly to this function, whereas Fail-open design is aimed at a failure mode in which access or traffic is allowed when a security control fails.
Incorrect Answers
Answer A is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The question is not asking for this function. It is testing a system that distributes client requests across multiple backend resources, so Load balancer is the stronger fit.
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The question is not asking for this function. It is testing a system that distributes client requests across multiple backend resources, so Load balancer is the stronger fit.
Answer D is incorrect because Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails. The key mismatch is functional: Load balancer addresses a system that distributes client requests across multiple backend resources, the need stated by the question.
Question 7
To enforce security decisions on live traffic, which security approach should be selected?
- Fail-open design
- Inline security device
- Attack-surface reduction
- Web application firewall (WAF)
Correct Answer: B
Correct Answer
Answer B is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The requirement maps directly to this function, whereas Attack-surface reduction is aimed at removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Incorrect Answers
Answer A is incorrect because Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails. This could be appropriate elsewhere, but the required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows; that makes Inline security device the precise choice.
Answer C is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. That concept can be valid in another scenario, but this question is testing a device placed directly in the traffic path so it can actively allow, block, or modify flows; Inline security device therefore fits the requirement more directly.
Answer D is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. That concept can be valid in another scenario, but this question is testing a device placed directly in the traffic path so it can actively allow, block, or modify flows; Inline security device therefore fits the requirement more directly.
Question 8
The control set for an enterprise network-security design review must address both security system that identifies suspicious activity and produces alerts but typically does not block traffic directly and cloud-delivered architecture combining networking and security capabilities near users and applications. Which TWO choices map directly to those needs? Choose TWO.
- Intrusion detection system (IDS)
- Proxy server
- Web application firewall (WAF)
- Inline security device
- Secure access service edge (SASE)
Correct Answers: A, E
Correct Answers
Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. It belongs in the fixed-count answer set because it covers one of the stated requirements. Web application firewall (WAF) instead serves a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic and cannot replace this function.
Answer E is correct because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications. It belongs in the fixed-count answer set because it covers one of the stated requirements. Web application firewall (WAF) instead serves a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The fixed-count answer set is Secure access service edge (SASE), Intrusion detection system (IDS); this option does not fill one of those named functions.
Answer C is incorrect because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. Every answer slot must map to a stated requirement. The correct set is Secure access service edge (SASE), Intrusion detection system (IDS), so this option cannot replace one of those selections.
Answer D is incorrect because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The fixed-count answer set is Secure access service edge (SASE), Intrusion detection system (IDS); this option does not fill one of those named functions.
Question 9
What is a failure mode in which access or traffic is allowed when a security control fails?
- Attack-surface reduction
- Extensible Authentication Protocol (EAP)
- Secure access service edge (SASE)
- Fail-open design
Correct Answer: D
Correct Answer
Answer D is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. The requirement maps directly to this function, whereas Extensible Authentication Protocol (EAP) is aimed at a framework that supports multiple authentication methods and is commonly used with 802.1X.
Incorrect Answers
Answer A is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. That concept can be valid in another scenario, but this question is testing a failure mode in which access or traffic is allowed when a security control fails; Fail-open design therefore fits the requirement more directly.
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. This could be appropriate elsewhere, but the required function is a failure mode in which access or traffic is allowed when a security control fails; that makes Fail-open design the precise choice.
Answer C is incorrect because Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications. The key mismatch is functional: Fail-open design addresses a failure mode in which access or traffic is allowed when a security control fails, the need stated by the question.
Question 10
To require identity-based authorization before granting normal wired or wireless network access, which security approach should be selected?
- 802.1X
- TLS tunnel
- Fail-closed design
- Layer 4 firewalling
Correct Answer: A
Correct Answer
Answer A is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. This matches the requirement as written. Fail-closed design can be valid in another context, but it is used for a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer B is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. That concept can be valid in another scenario, but this question is testing a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server; 802.1X therefore fits the requirement more directly.
Answer C is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. That concept can be valid in another scenario, but this question is testing a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server; 802.1X therefore fits the requirement more directly.
Answer D is incorrect because Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. The concept is valid, but it does not match this stem. The required function is a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server, which maps to 802.1X.
Question 11
To carry authentication exchanges for enterprise network access, which security approach should be selected?
- Fail-closed design
- 802.1X
- Proxy server
- Extensible Authentication Protocol (EAP)
Correct Answer: D
Correct Answer
Answer D is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. The deciding point is functional fit: this option covers the stated need, while Proxy server addresses an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer A is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. The scenario instead requires a framework that supports multiple authentication methods and is commonly used with 802.1X, which is why Extensible Authentication Protocol (EAP) is the better answer; this option serves the different function defined above.
Answer B is incorrect because 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. The key mismatch is functional: Extensible Authentication Protocol (EAP) addresses a framework that supports multiple authentication methods and is commonly used with 802.1X, the need stated by the question.
Answer C is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The scenario instead requires a framework that supports multiple authentication methods and is commonly used with 802.1X, which is why Extensible Authentication Protocol (EAP) is the better answer; this option serves the different function defined above. This question specifically tests the requirement represented by Extensible Authentication Protocol (EAP).
Question 12
Two requirements remain open in an enterprise network-security design review: hardened intermediary host used as a controlled administrative entry point to protected systems; intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. Which TWO options close those specific gaps? Choose TWO.
- Proxy server
- SD-WAN
- Tap or monitor deployment
- Jump server
- Virtual private network (VPN)
Correct Answers: A, D
Correct Answers
Answer A is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. One required function is exactly what this option provides. Tap or monitor deployment may be useful elsewhere, but it is used for a passive observation design that receives copies of traffic without sitting directly in the forwarding path.
Answer D is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. This option satisfies a specific requirement in the stem; SD-WAN serves software-defined wide-area networking that centrally manages traffic paths across multiple WAN links and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. The question requires exactly 2 selections: Jump server, Proxy server. This option falls outside that required set. For example, Jump server is required for a hardened intermediary host used as a controlled administrative entry point to protected systems.
Answer C is incorrect because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. The scenario calls for Jump server, Proxy server. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. The fixed-count answer set is Jump server, Proxy server; this option does not fill one of those named functions. For example, Jump server is required for a hardened intermediary host used as a controlled administrative entry point to protected systems.
Question 13
Reviewers working through an enterprise network-security design review identify three separate needs: device placed directly in the traffic path so it can actively allow, block, or modify flows; encrypted logical connection across an untrusted network; suite of network-layer protocols used to authenticate and encrypt IP traffic. Which THREE choices map to those needs? Choose THREE.
- Proxy server
- Jump server
- TLS tunnel
- Virtual private network (VPN)
- IPsec tunnel
- Inline security device
Correct Answers: D, E, F
Correct Answers
Answer D is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. This selection maps directly to one of the named needs. Proxy server addresses an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection, so it does not satisfy the same slot.
Answer E is correct because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. It belongs in the fixed-count answer set because it covers one of the stated requirements. TLS tunnel instead serves encrypted transport using Transport Layer Security to protect application communication and cannot replace this function.
Answer F is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. It belongs in the fixed-count answer set because it covers one of the stated requirements. Proxy server instead serves an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The required choices are Inline security device, IPsec tunnel, Virtual private network (VPN). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. Every answer slot must map to a stated requirement. The correct set is Inline security device, IPsec tunnel, Virtual private network (VPN), so this option cannot replace one of those selections.
Answer C is incorrect because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication. The scenario calls for Inline security device, IPsec tunnel, Virtual private network (VPN). Selecting this option would leave one of those required functions uncovered.
Question 14
What is an encrypted logical connection across an untrusted network?
- Virtual private network (VPN)
- IPsec tunnel
- Attack-surface reduction
- Unified threat management (UTM)
Correct Answer: A
Correct Answer
Answer A is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. That is the function the question is testing. IPsec tunnel would instead be used for a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Incorrect Answers
Answer B is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. This could be appropriate elsewhere, but the required function is an encrypted logical connection across an untrusted network; that makes Virtual private network (VPN) the precise choice.
Answer C is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The key mismatch is functional: Virtual private network (VPN) addresses an encrypted logical connection across an untrusted network, the need stated by the question.
Answer D is incorrect because Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. That concept can be valid in another scenario, but this question is testing an encrypted logical connection across an untrusted network; Virtual private network (VPN) therefore fits the requirement more directly.
Question 15
Which security appliance combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention?
- Jump server
- 802.1X
- Fail-closed design
- Unified threat management (UTM)
Correct Answer: D
Correct Answer
Answer D is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The requirement maps directly to this function, whereas Fail-closed design is aimed at a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer A is incorrect because Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems. The key mismatch is functional: Unified threat management (UTM) addresses a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, the need stated by the question.
Answer B is incorrect because 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. The concept is valid, but it does not match this stem. The required function is a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, which maps to Unified threat management (UTM).
Answer C is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. The key mismatch is functional: Unified threat management (UTM) addresses a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, the need stated by the question.
Question 16
The control set for an enterprise network-security design review must address both removal or restriction of unnecessary reachable services, interfaces, paths, or functionality and encrypted logical connection across an untrusted network. Which TWO choices map directly to those needs? Choose TWO.
- Attack-surface reduction
- Virtual private network (VPN)
- Security zone
- Layer 7 firewalling
- Layer 4 firewalling
Correct Answers: A, B
Correct Answers
Answer A is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The fixed-count item needs this function in the answer set. Layer 4 firewalling covers traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state, a different requirement.
Answer B is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. This option satisfies a specific requirement in the stem; Layer 4 firewalling serves traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state and therefore is not interchangeable with it.
Incorrect Answers
Answer C is incorrect because Security zone means a logical or physical area containing systems with similar trust or security requirements. Every answer slot must map to a stated requirement. The correct set is Virtual private network (VPN), Attack-surface reduction, so this option cannot replace one of those selections.
Answer D is incorrect because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content. The question requires exactly 2 selections: Virtual private network (VPN), Attack-surface reduction. This option falls outside that required set. For example, Virtual private network (VPN) is required for an encrypted logical connection across an untrusted network.
Answer E is incorrect because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. The fixed-count answer set is Virtual private network (VPN), Attack-surface reduction; this option does not fill one of those named functions.
Question 17
What is a cloud-delivered architecture combining networking and security capabilities near users and applications?
- Secure access service edge (SASE)
- Web application firewall (WAF)
- Proxy server
- Layer 7 firewalling
Correct Answer: A
Correct Answer
Answer A is correct because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications. This matches the requirement as written. Proxy server can be valid in another context, but it is used for an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer B is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The question is not asking for this function. It is testing a cloud-delivered architecture combining networking and security capabilities near users and applications, so Secure access service edge (SASE) is the stronger fit.
Answer C is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The concept is valid, but it does not match this stem. The required function is a cloud-delivered architecture combining networking and security capabilities near users and applications, which maps to Secure access service edge (SASE).
Answer D is incorrect because Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content. This could be appropriate elsewhere, but the required function is a cloud-delivered architecture combining networking and security capabilities near users and applications; that makes Secure access service edge (SASE) the precise choice.
Question 18
To decrease the number of opportunities available to an attacker, which security approach should be selected?
- Tap or monitor deployment
- Attack-surface reduction
- Inline security device
- 802.1X
Correct Answer: B
Correct Answer
Answer B is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. That is the function the question is testing. 802.1X would instead be used for a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Incorrect Answers
Answer A is incorrect because Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path. The key mismatch is functional: Attack-surface reduction addresses removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, the need stated by the question.
Answer C is incorrect because Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows. The question is not asking for this function. It is testing removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, so Attack-surface reduction is the stronger fit.
Answer D is incorrect because 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. That concept can be valid in another scenario, but this question is testing removal or restriction of unnecessary reachable services, interfaces, paths, or functionality; Attack-surface reduction therefore fits the requirement more directly.
Question 19
A review during an enterprise network-security design review identifies two gaps. One requires hardened intermediary host used as a controlled administrative entry point to protected systems. The other requires security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. Which TWO options should be included in the remediation plan? Choose TWO.
- TLS tunnel
- Jump server
- Load balancer
- 802.1X
- Intrusion detection system (IDS)
Correct Answers: B, E
Correct Answers
Answer B is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. One required function is exactly what this option provides. TLS tunnel may be useful elsewhere, but it is used for encrypted transport using Transport Layer Security to protect application communication.
Answer E is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. It belongs in the fixed-count answer set because it covers one of the stated requirements. Load balancer instead serves a system that distributes client requests across multiple backend resources and cannot replace this function.
Incorrect Answers
Answer A is incorrect because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication. The required choices are Jump server, Intrusion detection system (IDS). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Load balancer means a system that distributes client requests across multiple backend resources. The fixed-count answer set is Jump server, Intrusion detection system (IDS); this option does not fill one of those named functions.
Answer D is incorrect because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. Every answer slot must map to a stated requirement. The correct set is Jump server, Intrusion detection system (IDS), so this option cannot replace one of those selections.
Question 20
To inspect traffic with minimal risk of interrupting network flow, which security approach should be selected?
- Attack-surface reduction
- Tap or monitor deployment
- Intrusion prevention system (IPS)
- Extensible Authentication Protocol (EAP)
Correct Answer: B
Correct Answer
Answer B is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. That makes it the best answer here; Intrusion prevention system (IPS) addresses a security system positioned to detect and actively block suspicious traffic, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. This could be appropriate elsewhere, but the required function is a passive observation design that receives copies of traffic without sitting directly in the forwarding path; that makes Tap or monitor deployment the precise choice.
Answer C is incorrect because Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic. The concept is valid, but it does not match this stem. The required function is a passive observation design that receives copies of traffic without sitting directly in the forwarding path, which maps to Tap or monitor deployment.
Answer D is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. That concept can be valid in another scenario, but this question is testing a passive observation design that receives copies of traffic without sitting directly in the forwarding path; Tap or monitor deployment therefore fits the requirement more directly.