SY0-701 exam dumps

SY0-701 practice question 102 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 102

Single answerMisconfiguration

A company migrated several internal web applications to a new reverse proxy in its DMZ. Two weeks later, the security team discovers that one of the applications is accessible from the internet without requiring authentication, even though the application itself was intended for internal HR staff only. Log review shows no exploit attempts or malware activity; instead, external users were simply able to browse directly to the application URL. The proxy configuration was recently changed to speed up deployment of new apps. Which of the following is the MOST likely cause of this exposure?

  1. A

    The reverse proxy was misconfigured with an overly permissive access control rule that allowed unauthenticated external requests to the HR application

  2. B

    The HR application was compromised through a buffer overflow that disabled authentication checks for internet users

  3. C

    The DNS server was poisoned, causing external users to be redirected to the internal HR application

  4. D

    The web server certificate expired, causing the reverse proxy to bypass authentication for availability

Show answer and explanation

Correct answer: A

Explanation

This question tests recognition of misconfiguration as a root cause of security exposure. When a service becomes accessible externally immediately after an infrastructure change, and there is no evidence of exploitation, the most likely cause is a configuration error. In this case, a reverse proxy or application gateway may have been configured with overly broad access rules, incorrect path publishing, or missing authentication requirements. Security best practices emphasize least privilege, change control, secure baseline configurations, and validation after deployment. Guidance from sources such as NIST SP 800-41 on boundary protection and NIST SP 800-123 on secure configuration management supports reviewing access control rules, published services, and authentication enforcement after changes. A key lesson is that misconfiguration can create significant exposure even when no attacker has exploited a software vulnerability.

  • A. Correct.

    Correct. This is the most likely explanation because the scenario specifically points to a recent configuration change on the reverse proxy and notes that there were no signs of exploitation. In real environments, exposing an internal application often results from permissive routing, access control lists, missing authentication enforcement, or publishing the wrong backend path. This is a classic misconfiguration issue rather than an attack.

  • B. Incorrect.

    Incorrect. A buffer overflow is a software vulnerability exploitation scenario, but the question explicitly states there is no evidence of exploit attempts or malware activity. The facts better support accidental exposure through configuration error rather than memory corruption leading to disabled authentication.

  • C. Incorrect.

    Incorrect. DNS poisoning can redirect users to malicious or unintended destinations, but it would not typically make an internal HR application broadly reachable from the internet by itself. The issue described is that the application was directly accessible through the newly deployed reverse proxy, which points to a publishing or access-rule misconfiguration rather than name resolution manipulation.

  • D. Incorrect.

    Incorrect. An expired certificate can cause trust warnings, service interruptions, or TLS negotiation problems, but it does not normally cause a reverse proxy to disable authentication. Choosing this option reflects a misconception that certificate problems automatically change authorization behavior. Authentication and certificate validity are separate controls in most architectures.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam