Topic 11 Practice Test 3 covers Securing Enterprise Infrastructure for CompTIA Security+ SY0-701 and maps to objective 3.2: Given a scenario, apply security principles to secure enterprise infrastructure. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To optimize and control branch connectivity while applying centralized policy, which security approach should be selected?
- Inline security device
- Extensible Authentication Protocol (EAP)
- SD-WAN
- 802.1X
Correct Answer: C
Correct Answer
Answer C is correct because SD-WAN means software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. That is the function the question is testing. 802.1X would instead be used for a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server.
Incorrect Answers
Answer A is incorrect because Inline security device refers to a device placed directly in the traffic path so it can actively allow, block, or modify flows. The scenario instead requires software-defined wide-area networking that centrally manages traffic paths across multiple WAN links, which is why SD-WAN is the better answer; this option serves the different function defined above.
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. That concept can be valid in another scenario, but this question is testing software-defined wide-area networking that centrally manages traffic paths across multiple WAN links; SD-WAN therefore fits the requirement more directly.
Answer D is incorrect because 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. The concept is valid, but it does not match this stem. The required function is software-defined wide-area networking that centrally manages traffic paths across multiple WAN links, which maps to SD-WAN.
Question 2
To control flows based on network and transport characteristics, which security approach should be selected?
- SD-WAN
- Intrusion prevention system (IPS)
- Intrusion detection system (IDS)
- Layer 4 firewalling
Correct Answer: D
Correct Answer
Answer D is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. The deciding point is functional fit: this option covers the stated need, while SD-WAN addresses software-defined wide-area networking that centrally manages traffic paths across multiple WAN links.
Incorrect Answers
Answer A is incorrect because SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. The scenario instead requires traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state, which is why Layer 4 firewalling is the better answer; this option serves the different function defined above.
Answer B is incorrect because Intrusion prevention system (IPS) refers to a security system positioned to detect and actively block suspicious traffic. The concept is valid, but it does not match this stem. The required function is traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state, which maps to Layer 4 firewalling.
Answer C is incorrect because Intrusion detection system (IDS) refers to a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. That concept can be valid in another scenario, but this question is testing traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state; Layer 4 firewalling therefore fits the requirement more directly.
Question 3
During an enterprise network-security design review, the team has two independent requirements: (1) logical or physical area containing systems with similar trust or security requirements; and (2) framework that supports multiple authentication methods and is commonly used with 802.1X. Which TWO choices best satisfy those requirements? Choose TWO.
- Fail-open design
- Extensible Authentication Protocol (EAP)
- Unified threat management (UTM)
- Security zone
- Attack-surface reduction
Correct Answers: B, D
Correct Answers
Answer B is correct because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. The fixed-count item needs this function in the answer set. Attack-surface reduction covers removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, a different requirement.
Answer D is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements. This selection maps directly to one of the named needs. Attack-surface reduction addresses removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. The scenario calls for Security zone, Extensible Authentication Protocol (EAP). Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The scenario calls for Security zone, Extensible Authentication Protocol (EAP). Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Attack-surface reduction means removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The fixed-count answer set is Security zone, Extensible Authentication Protocol (EAP); this option does not fill one of those named functions.
Question 4
The team is resolving a gap found during an enterprise network-security design review: it needs device placed directly in the traffic path so it can actively allow, block, or modify flows. Which option is most appropriate?
- Load balancer
- Jump server
- Inline security device
- Fail-closed design
Correct Answer: C
Correct Answer
Answer C is correct because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The requirement maps directly to this function, whereas Fail-closed design is aimed at a failure mode in which access or traffic is blocked when a security control fails.
Incorrect Answers
Answer A is incorrect because Load balancer means a system that distributes client requests across multiple backend resources. This could be appropriate elsewhere, but the required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows; that makes Inline security device the precise choice.
Answer B is incorrect because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. This could be appropriate elsewhere, but the required function is a device placed directly in the traffic path so it can actively allow, block, or modify flows; that makes Inline security device the precise choice.
Answer D is incorrect because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. That concept can be valid in another scenario, but this question is testing a device placed directly in the traffic path so it can actively allow, block, or modify flows; Inline security device therefore fits the requirement more directly.
Question 5
To centralize and monitor privileged remote management access, which security approach should be selected?
- TLS tunnel
- Extensible Authentication Protocol (EAP)
- Security zone
- Jump server
Correct Answer: D
Correct Answer
Answer D is correct because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. That is the function the question is testing. TLS tunnel would instead be used for encrypted transport using Transport Layer Security to protect application communication.
Incorrect Answers
Answer A is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. This could be appropriate elsewhere, but the required function is a hardened intermediary host used as a controlled administrative entry point to protected systems; that makes Jump server the precise choice. This question specifically tests the requirement represented by Jump server.
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The key mismatch is functional: Jump server addresses a hardened intermediary host used as a controlled administrative entry point to protected systems, the need stated by the question.
Answer C is incorrect because Security zone refers to a logical or physical area containing systems with similar trust or security requirements. The concept is valid, but it does not match this stem. The required function is a hardened intermediary host used as a controlled administrative entry point to protected systems, which maps to Jump server.
Question 6
The team is resolving a gap found during an enterprise network-security design review: it needs security system positioned to detect and actively block suspicious traffic. Which option is most appropriate?
- Intrusion detection system (IDS)
- Extensible Authentication Protocol (EAP)
- Intrusion prevention system (IPS)
- Fail-open design
Correct Answer: C
Correct Answer
Answer C is correct because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic. The requirement maps directly to this function, whereas Fail-open design is aimed at a failure mode in which access or traffic is allowed when a security control fails.
Incorrect Answers
Answer A is incorrect because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. That concept can be valid in another scenario, but this question is testing a security system positioned to detect and actively block suspicious traffic; Intrusion prevention system (IPS) therefore fits the requirement more directly.
Answer B is incorrect because Extensible Authentication Protocol (EAP) means a framework that supports multiple authentication methods and is commonly used with 802.1X. The key mismatch is functional: Intrusion prevention system (IPS) addresses a security system positioned to detect and actively block suspicious traffic, the need stated by the question.
Answer D is incorrect because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. The question is not asking for this function. It is testing a security system positioned to detect and actively block suspicious traffic, so Intrusion prevention system (IPS) is the stronger fit.
Question 7
A security plan created during an enterprise network-security design review must provide security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention, traffic filtering that understands application-layer protocols and content, and encrypted logical connection across an untrusted network. Which THREE options should be selected? Choose THREE.
- Layer 7 firewalling
- Layer 4 firewalling
- Fail-closed design
- Virtual private network (VPN)
- Next-generation firewall (NGFW)
- Unified threat management (UTM)
Correct Answers: A, D, F
Correct Answers
Answer A is correct because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content. The fixed-count item needs this function in the answer set. Next-generation firewall (NGFW) covers a firewall that combines stateful filtering with application awareness and advanced inspection features, a different requirement.
Answer D is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. It belongs in the fixed-count answer set because it covers one of the stated requirements. Layer 4 firewalling instead serves traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state and cannot replace this function.
Answer F is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The fixed-count item needs this function in the answer set. Fail-closed design covers a failure mode in which access or traffic is blocked when a security control fails, a different requirement.
Incorrect Answers
Answer B is incorrect because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. Every answer slot must map to a stated requirement. The correct set is Unified threat management (UTM), Virtual private network (VPN), Layer 7 firewalling, so this option cannot replace one of those selections.
Answer C is incorrect because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. The fixed-count answer set is Unified threat management (UTM), Virtual private network (VPN), Layer 7 firewalling; this option does not fill one of those named functions.
Answer E is incorrect because Next-generation firewall (NGFW) means a firewall that combines stateful filtering with application awareness and advanced inspection features. Every answer slot must map to a stated requirement. The correct set is Unified threat management (UTM), Virtual private network (VPN), Layer 7 firewalling, so this option cannot replace one of those selections.
Question 8
To preserve security even if a control malfunction interrupts service, which security approach should be selected?
- 802.1X
- Web application firewall (WAF)
- Fail-closed design
- Load balancer
Correct Answer: C
Correct Answer
Answer C is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. That makes it the best answer here; 802.1X addresses a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because 802.1X refers to a standards-based framework for port-based network access control using an authenticator, supplicant, and authentication server. This could be appropriate elsewhere, but the required function is a failure mode in which access or traffic is blocked when a security control fails; that makes Fail-closed design the precise choice.
Answer B is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The question is not asking for this function. It is testing a failure mode in which access or traffic is blocked when a security control fails, so Fail-closed design is the stronger fit.
Answer D is incorrect because Load balancer refers to a system that distributes client requests across multiple backend resources. The question is not asking for this function. It is testing a failure mode in which access or traffic is blocked when a security control fails, so Fail-closed design is the stronger fit.
Question 9
To apply policy based on application behavior, commands, users, or content, which security approach should be selected?
- Fail-closed design
- Attack-surface reduction
- Web application firewall (WAF)
- Layer 7 firewalling
Correct Answer: D
Correct Answer
Answer D is correct because Layer 7 firewalling means traffic filtering that understands application-layer protocols and content. This matches the requirement as written. Web application firewall (WAF) can be valid in another context, but it is used for a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Incorrect Answers
Answer A is incorrect because Fail-closed design refers to a failure mode in which access or traffic is blocked when a security control fails. The question is not asking for this function. It is testing traffic filtering that understands application-layer protocols and content, so Layer 7 firewalling is the stronger fit.
Answer B is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. The scenario instead requires traffic filtering that understands application-layer protocols and content, which is why Layer 7 firewalling is the better answer; this option serves the different function defined above.
Answer C is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The concept is valid, but it does not match this stem. The required function is traffic filtering that understands application-layer protocols and content, which maps to Layer 7 firewalling.
Question 10
To apply consistent controls between groups of assets with different risk levels, which security approach should be selected?
- Jump server
- Security zone
- IPsec tunnel
- TLS tunnel
Correct Answer: B
Correct Answer
Answer B is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements. This is the precise fit for the scenario. TLS tunnel serves the different purpose of encrypted transport using Transport Layer Security to protect application communication.
Incorrect Answers
Answer A is incorrect because Jump server refers to a hardened intermediary host used as a controlled administrative entry point to protected systems. The key mismatch is functional: Security zone addresses a logical or physical area containing systems with similar trust or security requirements, the need stated by the question.
Answer C is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. The concept is valid, but it does not match this stem. The required function is a logical or physical area containing systems with similar trust or security requirements, which maps to Security zone.
Answer D is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. The key mismatch is functional: Security zone addresses a logical or physical area containing systems with similar trust or security requirements, the need stated by the question.
Question 11
To preserve availability when interruption is considered more harmful than reduced enforcement, which security approach should be selected?
- Virtual private network (VPN)
- Secure access service edge (SASE)
- Tap or monitor deployment
- Fail-open design
Correct Answer: D
Correct Answer
Answer D is correct because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. That is the function the question is testing. Virtual private network (VPN) would instead be used for an encrypted logical connection across an untrusted network.
Incorrect Answers
Answer A is incorrect because Virtual private network (VPN) refers to an encrypted logical connection across an untrusted network. The concept is valid, but it does not match this stem. The required function is a failure mode in which access or traffic is allowed when a security control fails, which maps to Fail-open design.
Answer B is incorrect because Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications. That concept can be valid in another scenario, but this question is testing a failure mode in which access or traffic is allowed when a security control fails; Fail-open design therefore fits the requirement more directly.
Answer C is incorrect because Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path. That concept can be valid in another scenario, but this question is testing a failure mode in which access or traffic is allowed when a security control fails; Fail-open design therefore fits the requirement more directly.
Question 12
The control set for an enterprise network-security design review must address both intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection and cloud-delivered architecture combining networking and security capabilities near users and applications. Which TWO choices map directly to those needs? Choose TWO.
- Fail-closed design
- Intrusion prevention system (IPS)
- Proxy server
- Web application firewall (WAF)
- Secure access service edge (SASE)
Correct Answers: C, E
Correct Answers
Answer C is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. The fixed-count item needs this function in the answer set. Fail-closed design covers a failure mode in which access or traffic is blocked when a security control fails, a different requirement.
Answer E is correct because Secure access service edge (SASE) means a cloud-delivered architecture combining networking and security capabilities near users and applications. One required function is exactly what this option provides. Web application firewall (WAF) may be useful elsewhere, but it is used for a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Incorrect Answers
Answer A is incorrect because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. The required choices are Secure access service edge (SASE), Proxy server. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Intrusion prevention system (IPS) means a security system positioned to detect and actively block suspicious traffic. The question requires exactly 2 selections: Secure access service edge (SASE), Proxy server. This option falls outside that required set.
Answer D is incorrect because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. Every answer slot must map to a stated requirement. The correct set is Secure access service edge (SASE), Proxy server, so this option cannot replace one of those selections.
Question 13
A remote-access gateway loses contact with its policy enforcement service. The organization requires the gateway to deny new sessions until the control recovers rather than permit traffic without inspection. Which design behavior satisfies this requirement?
- Fail-closed design
- SD-WAN
- Secure access service edge (SASE)
- IPsec tunnel
Correct Answer: A
Correct Answer
Answer A is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. That makes it the best answer here; Secure access service edge (SASE) addresses a cloud-delivered architecture combining networking and security capabilities near users and applications, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because SD-WAN refers to software-defined wide-area networking that centrally manages traffic paths across multiple WAN links. The question is not asking for this function. It is testing a failure mode in which access or traffic is blocked when a security control fails, so Fail-closed design is the stronger fit.
Answer C is incorrect because Secure access service edge (SASE) refers to a cloud-delivered architecture combining networking and security capabilities near users and applications. The concept is valid, but it does not match this stem. The required function is a failure mode in which access or traffic is blocked when a security control fails, which maps to Fail-closed design.
Answer D is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. The concept is valid, but it does not match this stem. The required function is a failure mode in which access or traffic is blocked when a security control fails, which maps to Fail-closed design.
Question 14
What is a logical or physical area containing systems with similar trust or security requirements?
- Security zone
- Extensible Authentication Protocol (EAP)
- Unified threat management (UTM)
- Web application firewall (WAF)
Correct Answer: A
Correct Answer
Answer A is correct because Security zone means a logical or physical area containing systems with similar trust or security requirements. That is the function the question is testing. Web application firewall (WAF) would instead be used for a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic.
Incorrect Answers
Answer B is incorrect because Extensible Authentication Protocol (EAP) refers to a framework that supports multiple authentication methods and is commonly used with 802.1X. The concept is valid, but it does not match this stem. The required function is a logical or physical area containing systems with similar trust or security requirements, which maps to Security zone.
Answer C is incorrect because Unified threat management (UTM) refers to a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. The key mismatch is functional: Security zone addresses a logical or physical area containing systems with similar trust or security requirements, the need stated by the question.
Answer D is incorrect because Web application firewall (WAF) refers to a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. That concept can be valid in another scenario, but this question is testing a logical or physical area containing systems with similar trust or security requirements; Security zone therefore fits the requirement more directly.
Question 15
An architect working on an enterprise network-security design review needs one capability that provides security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention and another that provides encrypted logical connection across an untrusted network. Which TWO selections are the best match? Choose TWO.
- Tap or monitor deployment
- Virtual private network (VPN)
- Load balancer
- Inline security device
- Unified threat management (UTM)
Correct Answers: B, E
Correct Answers
Answer B is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. This option satisfies a specific requirement in the stem; Tap or monitor deployment serves a passive observation design that receives copies of traffic without sitting directly in the forwarding path and therefore is not interchangeable with it.
Answer E is correct because Unified threat management (UTM) means a security appliance that combines several functions such as firewalling, filtering, malware scanning, and intrusion prevention. It belongs in the fixed-count answer set because it covers one of the stated requirements. Tap or monitor deployment instead serves a passive observation design that receives copies of traffic without sitting directly in the forwarding path and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. Every answer slot must map to a stated requirement. The correct set is Unified threat management (UTM), Virtual private network (VPN), so this option cannot replace one of those selections.
Answer C is incorrect because Load balancer means a system that distributes client requests across multiple backend resources. The scenario calls for Unified threat management (UTM), Virtual private network (VPN). Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The required choices are Unified threat management (UTM), Virtual private network (VPN). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 16
During an enterprise network-security design review, the team has two independent requirements: (1) passive observation design that receives copies of traffic without sitting directly in the forwarding path; and (2) encrypted logical connection across an untrusted network. Which TWO choices best satisfy those requirements? Choose TWO.
- Virtual private network (VPN)
- Fail-open design
- IPsec tunnel
- TLS tunnel
- Tap or monitor deployment
Correct Answers: A, E
Correct Answers
Answer A is correct because Virtual private network (VPN) means an encrypted logical connection across an untrusted network. This option satisfies a specific requirement in the stem; IPsec tunnel serves a suite of network-layer protocols used to authenticate and encrypt IP traffic and therefore is not interchangeable with it.
Answer E is correct because Tap or monitor deployment means a passive observation design that receives copies of traffic without sitting directly in the forwarding path. This option satisfies a specific requirement in the stem; TLS tunnel serves encrypted transport using Transport Layer Security to protect application communication and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Fail-open design means a failure mode in which access or traffic is allowed when a security control fails. The question requires exactly 2 selections: Virtual private network (VPN), Tap or monitor deployment. This option falls outside that required set.
Answer C is incorrect because IPsec tunnel means a suite of network-layer protocols used to authenticate and encrypt IP traffic. The question requires exactly 2 selections: Virtual private network (VPN), Tap or monitor deployment. This option falls outside that required set.
Answer D is incorrect because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication. The question requires exactly 2 selections: Virtual private network (VPN), Tap or monitor deployment. This option falls outside that required set.
Question 17
What is a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic?
- Load balancer
- Web application firewall (WAF)
- TLS tunnel
- Fail-open design
Correct Answer: B
Correct Answer
Answer B is correct because Web application firewall (WAF) means a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic. The deciding point is functional fit: this option covers the stated need, while Load balancer addresses a system that distributes client requests across multiple backend resources.
Incorrect Answers
Answer A is incorrect because Load balancer refers to a system that distributes client requests across multiple backend resources. The scenario instead requires a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, which is why Web application firewall (WAF) is the better answer; this option serves the different function defined above.
Answer C is incorrect because TLS tunnel refers to encrypted transport using Transport Layer Security to protect application communication. The question is not asking for this function. It is testing a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, so Web application firewall (WAF) is the stronger fit.
Answer D is incorrect because Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails. The concept is valid, but it does not match this stem. The required function is a firewall specialized for inspecting and filtering HTTP and HTTPS application traffic, which maps to Web application firewall (WAF).
Question 18
The control set for an enterprise network-security design review must address both failure mode in which access or traffic is blocked when a security control fails and traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. Which TWO choices map directly to those needs? Choose TWO.
- TLS tunnel
- Fail-closed design
- Jump server
- Inline security device
- Layer 4 firewalling
Correct Answers: B, E
Correct Answers
Answer B is correct because Fail-closed design means a failure mode in which access or traffic is blocked when a security control fails. The fixed-count item needs this function in the answer set. TLS tunnel covers encrypted transport using Transport Layer Security to protect application communication, a different requirement.
Answer E is correct because Layer 4 firewalling means traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. It belongs in the fixed-count answer set because it covers one of the stated requirements. TLS tunnel instead serves encrypted transport using Transport Layer Security to protect application communication and cannot replace this function.
Incorrect Answers
Answer A is incorrect because TLS tunnel means encrypted transport using Transport Layer Security to protect application communication. The question requires exactly 2 selections: Layer 4 firewalling, Fail-closed design. This option falls outside that required set. For example, Layer 4 firewalling is required for traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state.
Answer C is incorrect because Jump server means a hardened intermediary host used as a controlled administrative entry point to protected systems. The fixed-count answer set is Layer 4 firewalling, Fail-closed design; this option does not fill one of those named functions.
Answer D is incorrect because Inline security device means a device placed directly in the traffic path so it can actively allow, block, or modify flows. The scenario calls for Layer 4 firewalling, Fail-closed design. Selecting this option would leave one of those required functions uncovered.
Question 19
To detect likely attacks while operating passively or out of band, which security approach should be selected?
- Intrusion detection system (IDS)
- Tap or monitor deployment
- Fail-open design
- IPsec tunnel
Correct Answer: A
Correct Answer
Answer A is correct because Intrusion detection system (IDS) means a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly. This matches the requirement as written. IPsec tunnel can be valid in another context, but it is used for a suite of network-layer protocols used to authenticate and encrypt IP traffic.
Incorrect Answers
Answer B is incorrect because Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path. The concept is valid, but it does not match this stem. The required function is a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly, which maps to Intrusion detection system (IDS).
Answer C is incorrect because Fail-open design refers to a failure mode in which access or traffic is allowed when a security control fails. The question is not asking for this function. It is testing a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly, so Intrusion detection system (IDS) is the stronger fit.
Answer D is incorrect because IPsec tunnel refers to a suite of network-layer protocols used to authenticate and encrypt IP traffic. This could be appropriate elsewhere, but the required function is a security system that identifies suspicious activity and produces alerts but typically does not block traffic directly; that makes Intrusion detection system (IDS) the precise choice.
Question 20
Which intermediary makes requests on behalf of clients and can enforce policy, filtering, or inspection?
- Tap or monitor deployment
- Proxy server
- Attack-surface reduction
- Layer 4 firewalling
Correct Answer: B
Correct Answer
Answer B is correct because Proxy server means an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection. That makes it the best answer here; Attack-surface reduction addresses removal or restriction of unnecessary reachable services, interfaces, paths, or functionality, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Tap or monitor deployment refers to a passive observation design that receives copies of traffic without sitting directly in the forwarding path. The scenario instead requires an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection, which is why Proxy server is the better answer; this option serves the different function defined above.
Answer C is incorrect because Attack-surface reduction refers to removal or restriction of unnecessary reachable services, interfaces, paths, or functionality. That concept can be valid in another scenario, but this question is testing an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection; Proxy server therefore fits the requirement more directly.
Answer D is incorrect because Layer 4 firewalling refers to traffic filtering focused primarily on transport-layer information such as TCP or UDP ports and connection state. The scenario instead requires an intermediary that makes requests on behalf of clients and can enforce policy, filtering, or inspection, which is why Proxy server is the better answer; this option serves the different function defined above.