Topic 11 Practice Test 1 covers Securing Enterprise Infrastructure for CompTIA Security+ SY0-701 and maps to objective 3.2: Given a scenario, apply security principles to secure enterprise infrastructure. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To consolidate multiple security controls into one managed platform, which security approach should be selected?
- Unified threat management (UTM)
- Layer 4 firewalling
- Intrusion prevention system (IPS)
- Intrusion detection system (IDS)
Correct Answer: A
Correct Answer
Answer A is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. This matches the requirement as written. Layer 4 firewalling can be valid in another context, but it is used for traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Incorrect Answers
Answer B is incorrect because Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. This could be appropriate elsewhere, but the required function is a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention; that makes Unified threat management (UTM) the precise choice.
Answer C is incorrect because Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic. The concept is valid, but it does not match this stem. The required function is a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, which maps to Unified threat management (UTM).
Answer D is incorrect because Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. The scenario instead requires a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, which is why Unified threat management (UTM) is the better answer; this option serves the different function defined above.
Question 2
Two requirements remain open in an enterprise network-security design review: logical or physical area containing systems with similar trust or security requirements; security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. Which TWO options close those specific gaps? Choose TWO.
- Secure access service edge (SASE)
- Security zone
- Intrusion detection system (IDS)
- Attack-surface reduction
- SD-WAN
Correct Answers: B, C
Correct Answers
Answer B is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements. This option satisfies a specific requirement in the stem; Attack-surface reduction serves removal or restriction of unnecessary reachable services, interfaces, paths, or functionality and therefore is not interchangeable with it.
Answer C is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. One required function is exactly what this option provides. Secure access service edge (SASE) may be useful elsewhere, but it is used for a cloud-delivered architecture combining networking and security capabilities near users and applications.
Incorrect Answers
Answer A is incorrect because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications. The question requires exactly 2 selections: Security zone, Intrusion detection system (IDS). This option falls outside that required set.
Answer D is incorrect because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The scenario calls for Security zone, Intrusion detection system (IDS). Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. Every answer slot must map to a stated requirement. The correct set is Security zone, Intrusion detection system (IDS), so this option cannot replace one of those selections.
Question 3
Which term describes traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state?
- Extensible Authentication Protocol (EAP)
- Layer 4 firewalling
- Jump server
- Proxy server
Correct Answer: B
Correct Answer
Answer B is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. That makes it the best answer here; Jump server addresses a hardened intermediary host used as a controlled administrative entry point to protected systems, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The question is not asking for this function. It is testing traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state, so Layer 4 firewalling is the stronger fit.
Answer C is incorrect because Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems. That concept can be valid in another scenario, but this question is testing traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state; Layer 4 firewalling therefore fits the requirement more directly.
Answer D is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The key mismatch is functional: Layer 4 firewalling addresses traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state, the need stated by the question.
Question 4
The control set for an enterprise network-security design review must address both device placed directly in the traffic path so it can actively allow, block, or modify flows and standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. Which TWO choices map directly to those needs? Choose TWO.
- Layer 4 firewalling
- Unified threat management (UTM)
- 802.1X
- Inline security device
- IPsec tunnel
Correct Answers: C, D
Correct Answers
Answer C is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. This option satisfies a specific requirement in the stem; IPsec tunnel serves a suite of network-layer protocols used to authenticate and encrypt IP traffic and therefore is not interchangeable with it.
Answer D is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. It belongs in the fixed-count answer set because it covers one of the stated requirements. Unified threat management (UTM) instead serves a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. Every answer slot must map to a stated requirement. The correct set is 802.1X, Inline security device, so this option cannot replace one of those selections.
Answer B is incorrect because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The scenario calls for 802.1X, Inline security device. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. The scenario calls for 802.1X, Inline security device. Selecting this option would leave one of those required functions uncovered.
Question 5
An architect working on an enterprise network-security design review needs one capability that provides intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection and another that provides software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. Which TWO selections are the best match? Choose TWO.
- Proxy server
- 802.1X
- Web application firewall (WAF)
- SD-WAN
- Fail-closed design
Correct Answers: A, D
Correct Answers
Answer A is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The fixed-count item needs this function in the answer set. Web application firewall (WAF) covers a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, a different requirement.
Answer D is correct because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. This option satisfies a specific requirement in the stem; 802.1X serves a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. The question requires exactly 2 selections: SD-WAN, Proxy server. This option falls outside that required set.
Answer C is incorrect because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The question requires exactly 2 selections: SD-WAN, Proxy server. This option falls outside that required set. For example, Proxy server is required for an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Answer E is incorrect because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. The required choices are SD-WAN, Proxy server. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 6
A review during an enterprise network-security design review identifies two gaps. One requires passive observation design that receives copies of traffic without sitting directly in the forwarding path. The other requires intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. Which TWO options should be included in the remediation plan? Choose TWO.
- Proxy server
- SD-WAN
- Extensible Authentication Protocol (EAP)
- 802.1X
- Tap or monitor deployment
Correct Answers: A, E
Correct Answers
Answer A is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. It belongs in the fixed-count answer set because it covers one of the stated requirements. 802.1X instead serves a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server and cannot replace this function.
Answer E is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. This option satisfies a specific requirement in the stem; Extensible Authentication Protocol (EAP) serves a framework that supports multiple authentication methods and is commonly used with 802.1X and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. The fixed-count answer set is Proxy server, Tap or monitor deployment; this option does not fill one of those named functions.
Answer C is incorrect because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. The scenario calls for Proxy server, Tap or monitor deployment. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. Every answer slot must map to a stated requirement. The correct set is Proxy server, Tap or monitor deployment, so this option cannot replace one of those selections.
Question 7
What is a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server?
- Layer 7 firewalling
- Security zone
- IPsec tunnel
- 802.1X
Correct Answer: D
Correct Answer
Answer D is correct because 802.1X means a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. This matches the requirement as written. IPsec tunnel can be valid in another context, but it is used for a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Incorrect Answers
Answer A is incorrect because Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content. That concept can be valid in another scenario, but this question is testing a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server; 802.1X therefore fits the requirement more directly.
Answer B is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. The question is not asking for this function. It is testing a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server, so 802.1X is the stronger fit.
Answer C is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. That concept can be valid in another scenario, but this question is testing a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server; 802.1X therefore fits the requirement more directly.
Question 8
To protect web applications from malicious requests such as injection and protocol abuse, which security approach should be selected?
- IPsec tunnel
- Proxy server
- Web application firewall (WAF)
- Virtual private network (VPN)
Correct Answer: C
Correct Answer
Answer C is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. That makes it the best answer here; Virtual private network (VPN) addresses an encrypted logical connection across an untrusted network, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. The key mismatch is functional: Web application firewall (WAF) addresses a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, the need stated by the question.
Answer B is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. That concept can be valid in another scenario, but this question is testing a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic; Web application firewall (WAF) therefore fits the requirement more directly.
Answer D is incorrect because Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network. The question is not asking for this function. It is testing a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, so Web application firewall (WAF) is the stronger fit.
Question 9
What is a device placed directly in the traffic path so it can actively allow, block, or modify flows?
- Tap or monitor deployment
- Inline security device
- Next-generation firewall (NGFW)
- Security zone
Correct Answer: B
Correct Answer
Answer B is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. This matches the requirement as written. Security zone can be valid in another context, but it is used for a logical or physical area containing systems with similar trust or security requirements.
Incorrect Answers
Answer A is incorrect because Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path. The concept is valid, but it does not match this stem. The required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows, which maps to Inline security device.
Answer C is incorrect because Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features. This could be appropriate elsewhere, but the required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows; that makes Inline security device the precise choice.
Answer D is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. This could be appropriate elsewhere, but the required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows; that makes Inline security device the precise choice.
Question 10
Which passive observation design receives copies of traffic without sitting directly in the forwarding path?
- Layer 7 firewalling
- Tap or monitor deployment
- Inline security device
- Next-generation firewall (NGFW)
Correct Answer: B
Correct Answer
Answer B is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. That makes it the best answer here; Next-generation firewall (NGFW) addresses a firewall that combines stateful filtering with application awareness and advanced inspection features, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content. The key mismatch is functional: Tap or monitor deployment addresses a passive observation design that receives copies of traffic without sitting directly in the forwarding path, the need stated by the question.
Answer C is incorrect because Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows. The question is not asking for this function. It is testing a passive observation design that receives copies of traffic without sitting directly in the forwarding path, so Tap or monitor deployment is the stronger fit.
Answer D is incorrect because Next-generation firewall (NGFW) refers to a firewall that combines stateful filtering with application awareness and advanced inspection features. The concept is valid, but it does not match this stem. The required function is a passive observation design that receives copies of traffic without sitting directly in the forwarding path, which maps to Tap or monitor deployment.
Question 11
To improve availability, capacity, and sometimes security by controlling service distribution, which security approach should be selected?
- Load balancer
- SD-WAN
- Attack-surface reduction
- Fail-closed design
Correct Answer: A
Correct Answer
Answer A is correct because Load balancer means a system that distributes client requests across multiple backend resources. That makes it the best answer here; Fail-closed design addresses a failure mode in which access or traffic is blocked when a security control fails, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. The question is not asking for this function. It is testing a system that distributes client requests across multiple backend resources, so Load balancer is the stronger fit.
Answer C is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. This could be appropriate elsewhere, but the required function is a system that distributes client requests across multiple backend resources; that makes Load balancer the precise choice.
Answer D is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. This could be appropriate elsewhere, but the required function is a system that distributes client requests across multiple backend resources; that makes Load balancer the precise choice.
Question 12
To control and observe application access between clients and destinations, which security approach should be selected?
- Fail-closed design
- Proxy server
- TLS tunnel
- Layer 7 firewalling
Correct Answer: B
Correct Answer
Answer B is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. That is the function the question is testing. Fail-closed design would instead be used for a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer A is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. This could be appropriate elsewhere, but the required function is an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection; that makes Proxy server the precise choice.
Answer C is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. The key mismatch is functional: Proxy server addresses an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection, the need stated by the question.
Answer D is incorrect because Layer 7 firewalling refers to traffic filtering that understands application-layer protocols and content. The scenario instead requires an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection, which is why Proxy server is the better answer; this option serves the different function defined above.
Question 13
Reviewers working through an enterprise network-security design review identify three separate needs: framework that supports multiple authentication methods and is commonly used with 802.1X; traffic filtering that understands application-layer protocols and content; suite of network-layer protocols used to authenticate and encrypt IP traffic. Which THREE choices map to those needs? Choose THREE.
- Unified threat management (UTM)
- IPsec tunnel
- Inline security device
- Layer 7 firewalling
- Extensible Authentication Protocol (EAP)
- Load balancer
Correct Answers: B, D, E
Correct Answers
Answer B is correct because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. The fixed-count item needs this function in the answer set. Load balancer covers a system that distributes client requests across multiple backend resources, a different requirement.
Answer D is correct because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content. This selection maps directly to one of the named needs. Inline security device addresses a device placed directly in the traffic path so it can actively allow, block, or modify flows, so it does not satisfy the same slot.
Answer E is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. It belongs in the fixed-count answer set because it covers one of the stated requirements. Load balancer instead serves a system that distributes client requests across multiple backend resources and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. Every answer slot must map to a stated requirement. The correct set is IPsec tunnel, Layer 7 firewalling, Extensible Authentication Protocol (EAP), so this option cannot replace one of those selections.
Answer C is incorrect because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The required choices are IPsec tunnel, Layer 7 firewalling, Extensible Authentication Protocol (EAP). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer F is incorrect because Load balancer means a system that distributes client requests across multiple backend resources. The scenario calls for IPsec tunnel, Layer 7 firewalling, Extensible Authentication Protocol (EAP). Selecting this option would leave one of those required functions uncovered.
Question 14
What is a suite of network-layer protocols used to authenticate and encrypt IP traffic?
- IPsec tunnel
- Proxy server
- Security zone
- Attack-surface reduction
Correct Answer: A
Correct Answer
Answer A is correct because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. This is the precise fit for the scenario. Attack-surface reduction serves the different purpose of removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Incorrect Answers
Answer B is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. That concept can be valid in another scenario, but this question is testing a suite of network-layer protocols used to authenticate and encrypt IP traffic; IPsec tunnel therefore fits the requirement more directly.
Answer C is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. This could be appropriate elsewhere, but the required function is a suite of network-layer protocols used to authenticate and encrypt IP traffic; that makes IPsec tunnel the precise choice.
Answer D is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The question is not asking for this function. It is testing a suite of network-layer protocols used to authenticate and encrypt IP traffic, so IPsec tunnel is the stronger fit.
Question 15
Which term describes removal or restriction of unnecessary reachable services, interfaces, paths, or functionality?
- Extensible Authentication Protocol (EAP)
- Intrusion prevention system (IPS)
- Attack-surface reduction
- IPsec tunnel
Correct Answer: C
Correct Answer
Answer C is correct because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The deciding point is functional fit: this option covers the stated need, while IPsec tunnel addresses a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Incorrect Answers
Answer A is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The scenario instead requires removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, which is why Attack-surface reduction is the better answer; this option serves the different function defined above.
Answer B is incorrect because Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic. The scenario instead requires removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, which is why Attack-surface reduction is the better answer; this option serves the different function defined above.
Answer D is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. The key mismatch is functional: Attack-surface reduction addresses removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, the need stated by the question.
Question 16
To enforce policy using deeper context than addresses and ports alone, which security approach should be selected?
- IPsec tunnel
- Load balancer
- Next-generation firewall (NGFW)
- Proxy server
Correct Answer: C
Correct Answer
Answer C is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features. This matches the requirement as written. Load balancer can be valid in another context, but it is used for a system that distributes client requests across multiple backend resources.
Incorrect Answers
Answer A is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. That concept can be valid in another scenario, but this question is testing a firewall that combines stateful filtering with application awareness and advanced inspection features; Next-generation firewall (NGFW) therefore fits the requirement more directly.
Answer B is incorrect because Load balancer refers to a system that distributes client requests across multiple backend resources. The scenario instead requires a firewall that combines stateful filtering with application awareness and advanced inspection features, which is why Next-generation firewall (NGFW) is the better answer; this option serves the different function defined above.
Answer D is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. This could be appropriate elsewhere, but the required function is a firewall that combines stateful filtering with application awareness and advanced inspection features; that makes Next-generation firewall (NGFW) the precise choice.
Question 17
Which firewall combines stateful filtering with application awareness and advanced inspection features?
- Extensible Authentication Protocol (EAP)
- Attack-surface reduction
- Fail-closed design
- Next-generation firewall (NGFW)
Correct Answer: D
Correct Answer
Answer D is correct because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features. This matches the requirement as written. Attack-surface reduction can be valid in another context, but it is used for removal or restriction of unnecessary reachable services, interfaces, paths, or functionality.
Incorrect Answers
Answer A is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. That concept can be valid in another scenario, but this question is testing a firewall that combines stateful filtering with application awareness and advanced inspection features; Next-generation firewall (NGFW) therefore fits the requirement more directly.
Answer B is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The concept is valid, but it does not match this stem. The required function is a firewall that combines stateful filtering with application awareness and advanced inspection features, which maps to Next-generation firewall (NGFW).
Answer C is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. This could be appropriate elsewhere, but the required function is a firewall that combines stateful filtering with application awareness and advanced inspection features; that makes Next-generation firewall (NGFW) the precise choice.
Question 18
The control set for an enterprise network-security design review must address both failure mode in which access or traffic is allowed when a security control fails and encrypted logical connection across an untrusted network. Which TWO choices map directly to those needs? Choose TWO.
- Fail-open design
- IPsec tunnel
- Extensible Authentication Protocol (EAP)
- Jump server
- Virtual private network (VPN)
Correct Answers: A, E
Correct Answers
Answer A is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. It belongs in the fixed-count answer set because it covers one of the stated requirements. Jump server instead serves a hardened intermediary host used as a controlled administrative entry point to protected systems and cannot replace this function.
Answer E is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. This option satisfies a specific requirement in the stem; Jump server serves a hardened intermediary host used as a controlled administrative entry point to protected systems and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. Every answer slot must map to a stated requirement. The correct set is Virtual private network (VPN), Fail-open design, so this option cannot replace one of those selections.
Answer C is incorrect because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. The fixed-count answer set is Virtual private network (VPN), Fail-open design; this option does not fill one of those named functions.
Answer D is incorrect because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. Every answer slot must map to a stated requirement. The correct set is Virtual private network (VPN), Fail-open design, so this option cannot replace one of those selections.
Question 19
Which framework supports multiple authentication methods and is commonly used with 802.1X?
- Security zone
- Proxy server
- Secure access service edge (SASE)
- Extensible Authentication Protocol (EAP)
Correct Answer: D
Correct Answer
Answer D is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. This matches the requirement as written. Proxy server can be valid in another context, but it is used for an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection.
Incorrect Answers
Answer A is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. The scenario instead requires a framework that supports multiple authentication methods and is commonly used with 802.1X, which is why Extensible Authentication Protocol (EAP) is the better answer; this option serves the different function defined above.
Answer B is incorrect because Proxy server refers to an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The scenario instead requires a framework that supports multiple authentication methods and is commonly used with 802.1X, which is why Extensible Authentication Protocol (EAP) is the better answer; this option serves the different function defined above.
Answer C is incorrect because Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications. The concept is valid, but it does not match this stem. The required function is a framework that supports multiple authentication methods and is commonly used with 802.1X, which maps to Extensible Authentication Protocol (EAP).
Question 20
Which hardened intermediary host is used as a controlled administrative entry point to protected systems?
- Jump server
- Security zone
- TLS tunnel
- Load balancer
Correct Answer: A
Correct Answer
Answer A is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. This is the precise fit for the scenario. Load balancer serves the different purpose of a system that distributes client requests across multiple backend resources.
Incorrect Answers
Answer B is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. That concept can be valid in another scenario, but this question is testing a hardened intermediary host used as a controlled administrative entry point to protected systems; Jump server therefore fits the requirement more directly.
Answer C is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. This could be appropriate elsewhere, but the required function is a hardened intermediary host used as a controlled administrative entry point to protected systems; that makes Jump server the precise choice.
Answer D is incorrect because Load balancer refers to a system that distributes client requests across multiple backend resources. The concept is valid, but it does not match this stem. The required function is a hardened intermediary host used as a controlled administrative entry point to protected systems, which maps to Jump server.