100-160 exam dumps

100-160 practice question 84 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 84

Select 3

Your organization is deploying a web server that must be accessible to the public but also needs to securely interact with an internal database server. Which of the following network security architecture components should you implement to minimize the risk of external threats while maintaining functionality?

  1. A

    Place the web server in a Demilitarized Zone (DMZ) and use a firewall to control traffic between the DMZ and internal network.

  2. B

    Deploy an Intrusion Prevention System (IPS) to monitor and block malicious traffic targeting the web server.

  3. C

    Host the web server directly on the internal network to reduce latency when it communicates with the database server.

  4. D

    Configure a honeypot to mimic the web server and capture potential attacker activity.

  5. E

    Use a reverse proxy server to handle incoming requests to the web server and inspect traffic for potential threats.

Show answer and explanation

Correct answers: A, B, E

Explanation

To securely deploy a web server that interacts with an internal database, it is critical to combine multiple security measures. Placing the server in a DMZ isolates it from the internal network, while using an IPS provides active protection against threats. A reverse proxy adds an additional inspection layer, ensuring only safe traffic reaches the server. Together, these components form a robust and secure network security architecture.

  • A. Correct.

    Placing the web server in a DMZ ensures it is isolated from the internal network while allowing controlled access to necessary resources. The firewall adds another layer of security by filtering traffic.

  • B. Correct.

    An IPS can detect and block malicious traffic targeting the web server, providing real-time protection against threats such as SQL injection or Distributed Denial of Service (DDoS) attacks.

  • C. Incorrect.

    Hosting the web server directly on the internal network is a poor security practice as it exposes critical internal systems to potential attacks. This option increases risk rather than reducing it.

  • D. Incorrect.

    A honeypot is designed to lure attackers and study their behavior, not to secure legitimate assets like a production web server. While useful for research, it does not protect the server itself.

  • E. Correct.

    A reverse proxy server adds security by inspecting incoming traffic and forwarding only legitimate requests to the web server, reducing the attack surface.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam