CompTIAAssociate levelSY0-701Page 3 of 5

SY0-701 exam dumps: questions 201 to 300 of 490

Page 3 of the free SY0-701 question bank for the Security+ exam. Questions 201 to 300 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated June 2026

Free SY0-701 practice questions

Questions 201 to 205 of 490

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

SY0-701 Question 201

Single answerFirewall types: Web application firewall (WAF) , Unified threat management (UTM) , Next-generation firewall (NGFW) , Layer 4/Layer 7

A retail company hosts an Internet-facing e-commerce application that recently experienced several attempts to exploit SQL injection and cross-site scripting vulnerabilities in its checkout pages. The security team also wants better visibility into encrypted web traffic and the ability to block risky applications at the perimeter. However, they do not want to replace the specialized control that best protects the web application itself. Which solution should the company deploy at the perimeter while keeping the most appropriate existing or additional control in front of the web application?

  1. A

    Deploy a next-generation firewall (NGFW) at the perimeter and keep or add a web application firewall (WAF) in front of the e-commerce application

  2. B

    Deploy a layer 4 firewall at the perimeter and remove any WAF because port-based filtering is sufficient for web attacks

  3. C

    Deploy a unified threat management (UTM) appliance at the perimeter and use it as a complete replacement for application-specific web protections

  4. D

    Deploy a layer 7 stateful packet filter at the perimeter and rely on it alone to stop SQL injection in the application code

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy an NGFW at the perimeter and keep or add a WAF in front of the e-commerce application. This reflects defense in depth and proper matching of controls to threats. NGFWs extend traditional firewall capabilities with features such as application awareness, integrated intrusion prevention, and often SSL/TLS inspection support, making them appropriate for perimeter enforcement and visibility. WAFs are purpose-built to protect web applications by inspecting HTTP/HTTPS traffic for attacks such as SQL injection, cross-site scripting, and other OWASP Top 10-style threats. By contrast, layer 4 firewalls focus on ports and protocols and are not sufficient for application-layer web attacks. UTM platforms provide all-in-one security capabilities, but on Security+ questions, the most appropriate answer typically aligns the control to the threat: WAF for web application attacks, NGFW for advanced perimeter control. This is consistent with common industry guidance from NIST and OWASP, which emphasize layered defenses and application-specific protections for Internet-facing web applications.

  • A. Correct.

    Correct. An NGFW is well suited for perimeter deployment when the organization needs application awareness, deeper inspection, and visibility into traffic, including capabilities commonly associated with controlling applications and inspecting encrypted traffic depending on configuration and licensing. A WAF remains the best specialized control for protecting web applications against attacks such as SQL injection and cross-site scripting because it understands HTTP/HTTPS requests and common web attack patterns. This layered approach matches real-world best practice: use an NGFW for broad network/perimeter security and a WAF for application-layer web protection.

  • B. Incorrect.

    Incorrect. A layer 4 firewall primarily makes decisions based on IP addresses, ports, and protocols, which is not sufficient to identify or stop application-layer attacks such as SQL injection or cross-site scripting. Removing a WAF would eliminate the control most specifically designed to inspect HTTP/HTTPS payloads for malicious web requests. This option reflects the misconception that transport-layer filtering can adequately protect modern web applications.

  • C. Incorrect.

    Incorrect. A UTM appliance can consolidate multiple security functions into one platform and may be appropriate for some environments, especially smaller organizations, but it is not the best answer here because the scenario explicitly calls for maintaining the specialized control best suited to protect the web application itself. Replacing application-specific web protections with only a UTM introduces risk because a dedicated WAF provides focused defenses for web-layer attacks that perimeter consolidation alone may not address with the same depth.

  • D. Incorrect.

    Incorrect. This option mixes concepts inaccurately. Layer 7 inspection can provide more context than layer 4, but simply relying on a perimeter device alone is not the most appropriate defense against SQL injection in a web application. A WAF is specifically designed to analyze and filter HTTP/HTTPS requests for malicious patterns targeting web applications. The misconception here is that any device with some application-layer awareness can fully replace a dedicated WAF.

SY0-701 Question 202

Single answerDevice attribute: Active vs. passive , Inline vs. tap/monitor

A security administrator needs to add a new network security device in front of a public web application that is frequently targeted by malicious requests. Management wants the device to actively stop suspicious traffic before it reaches the servers. However, the administrator is also evaluating a separate monitoring solution for the core switch that must observe traffic without introducing latency or creating a point of failure in the production path. Which combination best meets both requirements?

  1. A

    Deploy an inline active device for the web application, and use a passive monitor connected through a network tap or SPAN port for the core switch

  2. B

    Deploy a passive monitor for the web application, and use an inline active device on the core switch so traffic can be copied for analysis

  3. C

    Deploy inline passive devices in both locations because inline placement does not affect traffic flow

  4. D

    Deploy active tap devices in both locations because taps can block malicious traffic while remaining out of band

Show answer and explanation

Correct answer: A

Explanation

This question tests the difference between active vs. passive and inline vs. monitor/tap deployments. In Security+ terms, an active security device can take action on traffic, while a passive device primarily observes and alerts. Inline devices are placed directly in the network path, which allows enforcement but can introduce latency or availability risk. Tap/monitor deployments are out of band; they receive copied traffic and are commonly used for IDS, packet capture, and network monitoring when visibility is needed without affecting production forwarding. In practice, organizations commonly deploy IPS, firewalls, or WAFs inline when they need prevention, and deploy IDS sensors or analyzers via network taps or SPAN ports when they need detection and visibility. This aligns with common vendor documentation and network security best practices: prevention requires in-path enforcement, while passive monitoring is preferred when minimizing operational impact is the priority.

  • A. Correct.

    Correct. An inline active device sits directly in the traffic path and can inspect and take action, such as blocking or dropping malicious requests before they reach the web application. This matches the requirement to actively stop suspicious traffic. For the core switch monitoring use case, a passive monitor connected through a network tap or a switch SPAN/mirror port can observe traffic without being part of the live forwarding path, which avoids adding latency and reduces the risk of becoming a single point of failure.

  • B. Incorrect.

    Incorrect. A passive monitor for the web application can observe and alert on malicious traffic, but it cannot directly prevent the traffic from reaching the servers because it is not enforcing inline. The second part is also flawed: placing an inline active device at the core switch would insert the tool into the production path, which conflicts with the requirement to avoid added latency and avoid creating a point of failure just for monitoring.

  • C. Incorrect.

    Incorrect. Inline placement means the device is in the traffic path, so it can affect traffic flow, latency, and availability. Calling such devices 'inline passive' is misleading in this context. If a device is truly passive for monitoring, it is typically out of band and receives copied traffic from a tap or mirror port rather than forwarding production traffic itself.

  • D. Incorrect.

    Incorrect. A network tap is generally used to copy traffic for monitoring and analysis; it does not normally block malicious traffic as a security control. The phrase 'active tap devices' combines concepts incorrectly. If the goal is to block traffic, the device must be inline and capable of active enforcement, such as an IPS or WAF deployed in the traffic path.

SY0-701 Question 203

Single answerDevice attribute: Active vs. passive , Inline vs. tap/monitor

A security administrator must deploy a new monitoring solution on a critical link between the core switch and the internet edge. Management requires that the device must be able to automatically block malicious traffic in real time, but the network team is concerned that placing anything directly in the traffic path could create a single point of failure. Which deployment best meets the requirement to stop attacks immediately while highlighting the primary tradeoff?

  1. A

    Deploy an active device inline; it can inspect and block traffic, but it may affect availability if the device fails or becomes overloaded.

  2. B

    Deploy a passive device on a network tap; it can block malicious traffic without being in the traffic path and avoids any availability risk.

  3. C

    Deploy a passive device using port mirroring; it can drop malicious packets before they reach the firewall while remaining out of band.

  4. D

    Deploy an active device on a network tap; it can terminate suspicious sessions and still remain completely isolated from production traffic.

Show answer and explanation

Correct answer: A

Explanation

The key distinction is between active vs. passive and inline vs. tap/monitor deployments. Active devices can affect traffic flow by blocking, dropping, resetting, or otherwise preventing malicious activity. To do that directly, they typically must be deployed inline, meaning traffic passes through them. Passive devices, such as IDS sensors connected via a network tap or SPAN/port mirror, analyze copied traffic and provide visibility and alerting but do not directly stop packets on that link.

In practice, an inline IPS best satisfies a requirement to block malicious traffic in real time. However, best-practice design considerations include high availability, bypass/fail-open or fail-closed behavior, capacity planning, and careful change control because inline devices can introduce performance and availability risks. This aligns with common vendor and industry guidance for IDS/IPS architecture: IDS is typically passive and out of band; IPS is typically active and inline.

  • A. Correct.

    Correct. An active security device, such as an inline IPS, sits directly in the traffic path and can take preventive action like dropping packets, resetting connections, or blocking traffic in real time. The tradeoff is that inline placement introduces potential latency and can create an availability concern if the device fails, is misconfigured, or is undersized. This directly matches the scenario's need for immediate blocking while acknowledging the network team's concern.

  • B. Incorrect.

    Incorrect. A passive device connected through a tap receives a copy of traffic for analysis but is not in the path of traffic flow. Because it is out of band, it generally cannot directly block packets traversing the link. This option reflects a common misconception that visibility alone enables prevention.

  • C. Incorrect.

    Incorrect. Port mirroring, like a network tap, is typically used for passive monitoring by sending copies of packets to a sensor. A passive device connected this way can detect and alert on malicious activity, but it cannot directly drop packets before they traverse the link. Someone might choose this option because SPAN/port mirroring is often associated with IDS deployments, but IDS monitoring is detective rather than preventive unless integrated with other enforcement controls.

  • D. Incorrect.

    Incorrect. A network tap is used to feed copied traffic to monitoring tools and supports passive visibility. An active device must be inline to directly enforce blocking on the traffic stream. While some platforms can send commands to other devices for response, that is not the same as directly terminating sessions from a passive tap position on the monitored link.

SY0-701 Question 204

Single answer

A company hosts a customer-facing web application behind a load balancer in its DMZ. Security analysts discover that attackers are sending crafted HTTP requests that attempt SQL injection against the application. Management wants a solution that can automatically detect and stop these malicious requests before they reach the web servers, without requiring code changes to the application. Which network appliance would BEST meet this requirement?

  1. A

    Deploy a network-based IPS inline between the internet edge and the web application segment

  2. B

    Require administrators to connect through a jump server before accessing the web application servers

  3. C

    Implement a proxy server to cache inbound web content before it reaches the application

  4. D

    Add additional sensors to collect copies of traffic for later security analysis

Show answer and explanation

Correct answer: A

Explanation

The key phrase in the scenario is 'automatically detect and stop these malicious requests before they reach the web servers.' That requirement points to an intrusion prevention system, not an intrusion detection system or passive sensor. An IPS is deployed inline so it can inspect packets and sessions and take preventive action such as dropping traffic, resetting connections, or blocking known attack signatures. By contrast, IDS and sensors are generally detective controls that provide alerting and visibility but do not block traffic themselves. A jump server is intended for administrative access control, not protection of public application traffic. A proxy server may sit between clients and servers, but unless the question explicitly describes a security-capable reverse proxy or web application firewall, the best Security+ answer for inline detection and prevention is an IPS. This aligns with common security architecture guidance, including NIST concepts distinguishing detective controls from preventive controls and vendor documentation describing IPS as an inline blocking technology.

  • A. Correct.

    Correct. A network-based intrusion prevention system (IPS) is designed to inspect traffic inline and can actively block malicious requests, such as known SQL injection patterns, before they reach the protected servers. This directly satisfies the requirement to both detect and stop attacks in real time without modifying the application itself.

  • B. Incorrect.

    Incorrect. A jump server is used to control and secure administrative access to internal systems, typically by serving as a hardened intermediary for remote management. It does not inspect or block customer HTTP requests to a public web application, so it would not mitigate SQL injection attempts from external attackers.

  • C. Incorrect.

    Incorrect. A proxy server can intermediate requests, enforce policy, or cache content depending on its role, but a generic proxy's primary purpose is not inline attack prevention. While some specialized reverse proxies may provide security features, the best answer in this scenario is an IPS because the requirement is specifically to detect and automatically block malicious traffic before it reaches the servers.

  • D. Incorrect.

    Incorrect. Sensors are commonly used for monitoring and visibility, often feeding data to IDS, SIEM, or other analysis platforms. However, sensors alone generally observe and report activity rather than actively prevent malicious traffic. They would help with detection and forensic review, but not with stopping the attack in real time.

SY0-701 Question 205

Single answer

A company hosts a customer-facing web application in a DMZ behind a load balancer. After a recent update, the security team discovers repeated SQL injection attempts coming from multiple external IP addresses. Management wants a solution that can automatically detect and stop these malicious requests before they reach the web servers, while still allowing legitimate traffic to pass. Which network appliance would BEST meet this requirement?

  1. A

    Jump server

  2. B

    Proxy server

  3. C

    Intrusion prevention system (IPS)

  4. D

    Network sensor connected to a monitoring port

Show answer and explanation

Correct answer: C

Explanation

The key phrase in the scenario is that the company wants to automatically detect and stop malicious requests before they reach the web servers. That requirement points to an IPS rather than an IDS or passive sensor. An IDS or network sensor can identify suspicious activity and generate alerts, but it usually does not sit inline to actively block traffic. A jump server serves a very different purpose: securing administrative access. A proxy server can provide request handling and filtering in some architectures, but on Security+ questions, when the requirement is to inspect live traffic and actively prevent attacks such as SQL injection, the best answer is an IPS. This aligns with common security architecture guidance, including NIST concepts around intrusion detection and prevention technologies, where IPS solutions are positioned inline to detect and take action on malicious traffic.

  • A. Incorrect.

    A jump server is used to provide controlled administrative access to internal systems, typically by acting as a hardened intermediary for remote management. It is not designed to inspect and block malicious application traffic such as SQL injection attempts targeting public web servers.

  • B. Incorrect.

    A proxy server can mediate client requests and may provide filtering, caching, or anonymity features depending on the implementation. However, a generic proxy server is not the best answer here because the requirement is specifically to automatically detect and block malicious traffic patterns before they reach the servers. That is the primary role of an IPS.

  • C. Correct.

    An intrusion prevention system (IPS) is correct because it is designed to inspect traffic inline and take preventive action, such as dropping or rejecting malicious packets or sessions. In this scenario, the company needs a control that both detects SQL injection attempts and stops them before they reach the web application, which aligns with IPS functionality.

  • D. Incorrect.

    A network sensor connected to a monitoring port is typically used for visibility, traffic collection, or detection when paired with monitoring tools, but by itself it is generally out-of-band and does not block traffic. This makes it useful for alerting and analysis, not for the required automatic prevention.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

SY0-701 practice questions 201 to 300 of 490

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 5 pages of up to 100 questions.

  1. 201.A retail company hosts an Internet-facing e-commerce application that recently experienced several attempts...
  2. 202.A security administrator needs to add a new network security device in front of a public web application that...
  3. 203.A security administrator must deploy a new monitoring solution on a critical link between the core switch and...
  4. 204.A company hosts a customer-facing web application behind a load balancer in its DMZ. Security analysts...
  5. 205.A company hosts a customer-facing web application in a DMZ behind a load balancer. After a recent update, the...
  6. 206.A company is deploying 802.1X port-based access control on access switches to prevent unauthorized devices...
  7. 207.A company is deploying 802.1X on access switch ports to prevent unauthorized devices from connecting to the...
  8. 208.A company is replacing its legacy remote-access VPN concentrator. The security team wants remote employees to...
  9. 209.A company is replacing a legacy remote-access VPN concentrator used by traveling employees. The security team...
  10. 210.A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications,...
  11. 211.A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications...
  12. 212.A healthcare company stores patient records in a cloud-based application that is accessed by employees,...
  13. 213.A healthcare company allows employees to use their own smartphones to access email and a patient scheduling...
  14. 214.A healthcare company is moving archived patient records from an on-premises file server to a cloud object...
  15. 215.A healthcare company is moving patient billing records from an on-premises file server to a cloud storage...
  16. 216.A software company is preparing a litigation hold and data protection plan after discovering that an engineer...
  17. 217.A security administrator is helping a company classify data before migrating several repositories to a cloud...
  18. 218.A healthcare company is revising its data handling standard after an employee accidentally emailed an...
  19. 219.A healthcare organization is updating its data handling standard after several employees shared files through...
  20. 220.A healthcare company is preparing to move several datasets into a cloud analytics platform so data scientists...
  21. 221.A healthcare organization is preparing to move several business processes to a third-party SaaS platform. The...
  22. 222.A healthcare organization stores patient records in a cloud-hosted database, allows clinicians to access the...
  23. 223.A healthcare organization is updating its security controls after an audit found gaps in how patient records...
  24. 224.A multinational company based in Germany is moving its customer records to a cloud-based SaaS platform....
  25. 225.A U.S.-based software company is migrating its customer records platform to a public cloud provider. The...
  26. 226.A company allows employees to access its cloud-based HR system remotely. The security team notices repeated...
  27. 227.A company has moved its payroll application to a cloud-hosted web portal. The security team notices repeated...
  28. 228.A healthcare company is migrating a customer support application to the cloud. Support agents need to look up...
  29. 229.A retail company is modernizing its e-commerce environment after an internal audit found that customer...
  30. 230.A healthcare provider was hit by ransomware that encrypted several virtual servers, including the primary...
  31. 231.A healthcare organization recently suffered a ransomware attack that encrypted several on-premises file...
  32. 232.An e-commerce company is redesigning its public web environment after a recent outage. The security team...
  33. 233.A company hosts a customer-facing web application that must remain available during peak shopping periods....
  34. 234.A regional healthcare provider is updating its disaster recovery plan after a ransomware incident caused a...
  35. 235.A regional healthcare provider is updating its disaster recovery plan after a ransomware incident caused a...
  36. 236.A healthcare organization wants to validate its disaster recovery plan for the electronic medical records...
  37. 237.A healthcare organization is preparing to test its disaster recovery capabilities for an electronic medical...
  38. 238.A financial services company is updating its business continuity plan after a regional power failure took its...
  39. 239.A financial services company is redesigning its disaster recovery strategy after a regional power outage took...
  40. 240.A company hosts its customer portal across two cloud providers to reduce the risk of a single-provider...
  41. 241.A company runs customer-facing applications in two different public cloud providers to improve resilience and...
  42. 242.A regional healthcare provider is hit by ransomware that encrypts several on-premises application servers in...
  43. 243.A regional healthcare provider is updating its continuity of operations plan after a ransomware incident made...
  44. 244.A healthcare company is expanding from one clinic to eight regional sites and must maintain 24/7 security...
  45. 245.A healthcare company is expanding from one clinic to eight regional locations over the next six months. The...
  46. 246.A company runs a customer order database on a virtualized server. After a recent ransomware incident,...
  47. 247.A company is hit by ransomware at 3:00 p.m. on Wednesday. The security administrator confirms the malware...
  48. 248.A regional office hosts security appliances, badge access controllers, and a small virtualization cluster in...
  49. 249.A company hosts its authentication servers and security monitoring systems in a small on-premises server...
  50. 250.A company is migrating several customer-facing applications to a public cloud provider. During a security...
  51. 251.A systems administrator is hardening a group of Linux-based web servers that host an internal business...
  52. 252.A security administrator is standardizing 500 newly issued Windows laptops for a hybrid workforce. The...
  53. 253.A security administrator is tasked with standardizing 600 newly deployed Windows laptops for a hybrid...
  54. 254.A manufacturing company is connecting a legacy ICS/SCADA segment to a new analytics platform hosted in the...
  55. 255.A manufacturing company is connecting new IoT environmental sensors to an existing ICS/SCADA network to...
  56. 256.A security administrator is hardening a company’s wireless network after discovering that employees can still...
  57. 257.A security administrator is investigating reports that employees' wireless headsets are intermittently...
  58. 258.A security administrator is deploying new wireless access points in a healthcare clinic that handles...
  59. 259.A security administrator is deploying a new WPA3-Enterprise wireless network in a multitenant office...
  60. 260.A company allows employees to use personal smartphones to access corporate email and documents. After several...
  61. 261.A company allows employees to use personal smartphones to access corporate email, calendars, and internally...
  62. 262.A healthcare company must provide mobile access to email, scheduling, and an internal clinical messaging app...
  63. 263.A healthcare company must allow clinicians to access email, messaging, and scheduling apps from mobile...
  64. 264.A security administrator is deploying tablets for field technicians who work in customer buildings and remote...
  65. 265.A healthcare organization issues tablets to nurses for bedside charting. The tablets normally use the...
  66. 266.A company is replacing its shared Wi-Fi password with a more secure solution for employee laptops and phones....
  67. 267.A security administrator is upgrading a corporate wireless network used by employee laptops and tablets. The...
  68. 268.A company is preparing to release an updated customer portal after a penetration test found two issues:...
  69. 269.A company is releasing a customer portal update after a security review found several issues. Testers...
  70. 270.A security analyst receives a suspicious spreadsheet attachment from a vendor email account that may have...
  71. 271.A security analyst receives a suspicious email attachment that appears to be an invoice PDF. The company...
  72. 272.A security analyst is tuning the company's monitoring program after several ransomware attempts were missed...
  73. 273.A security analyst is tuning the company’s monitoring strategy after a recent incident in which an attacker...
  74. 274.A healthcare company is preparing for an external audit after discovering that several retired laptops...
  75. 275.A healthcare company is preparing for an external audit after discovering that several laptops issued to...
  76. 276.A healthcare company is acquiring a cloud-based document management platform to store contracts, HR files,...
  77. 277.A company is procuring a cloud-based document management platform to store contracts, customer records, and...
  78. 278.A security administrator is reviewing remote-access controls for a company that uses a centralized AAA server...
  79. 279.A security administrator is reviewing remote-access controls for a company VPN that uses a AAA framework with...
  80. 280.A company is updating its information security program after a failed audit found that several critical...
  81. 281.A company is preparing for a compliance audit after several incidents in which critical customer records were...
  82. 282.A healthcare company is rolling out a data handling policy after discovering that employees store patient...
  83. 283.A healthcare organization is implementing a new data handling standard after discovering that staff have been...
  84. 284.A security administrator is responding to an incident involving a contractor's laptop that accessed sensitive...
  85. 285.A security administrator discovers that several company laptops are appearing on the wireless network after...
  86. 286.A security administrator is responding to a ransomware incident and discovers several engineering...
  87. 287.A security administrator is preparing for a vulnerability management initiative after several unmanaged...
  88. 288.A security analyst is reviewing the results of an internal assessment on a Windows-based network. The tester...
  89. 289.A security analyst is validating the scope of an internal penetration test and wants to identify exposed...
  90. 290.A healthcare organization is retiring several storage systems from a claims-processing environment. The...
  91. 291.A healthcare organization is retiring several storage systems after a data center refresh. The environment...
  92. 292.A healthcare company is reviewing its security logging strategy after an incident investigation failed...
  93. 293.A healthcare company is reviewing its log management process after an incident response exercise revealed...
  94. 294.A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web...
  95. 295.A security analyst runs a credentialed vulnerability scan against a group of internet-facing Linux web...
  96. 296.A software company is preparing to release a new customer portal built with several open-source libraries....
  97. 297.A software company is preparing to release a new customer portal within two weeks. During final testing, the...
  98. 298.A security analyst at a healthcare company reviews the weekly vulnerability scan results. The scanner reports...
  99. 299.A security analyst at a healthcare company reviews the latest vulnerability scan results. The scanner reports...
  100. 300.A hospital's security team identifies a critical remote code execution vulnerability on a legacy radiology...