SY0-701 exam dumps

SY0-701 practice question 124 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 124

Single answer2.5 Explain the purpose of mitigation techniques used to secure the enterprise.

A company is rolling out a new customer support platform. The application must be reachable from the internet, but the security team wants to reduce the risk that a compromise of the web server could allow an attacker to move laterally into the internal network. The company also wants to limit direct inbound access to internal application and database servers. Which mitigation technique BEST addresses this requirement?

  1. A

    Place the public-facing web server in a screened subnet (DMZ) and restrict traffic to the internal network with firewall rules

  2. B

    Implement full-disk encryption on the web server to prevent lateral movement from the internet

  3. C

    Require multifactor authentication for administrators who manage the support platform

  4. D

    Deploy a host-based antivirus solution on the internal database server

Show answer and explanation

Correct answer: A

Explanation

The best answer is to place the internet-facing system in a DMZ and enforce restrictive firewall rules between network segments. In Security+ objectives covering enterprise mitigation techniques, segmentation is a core concept used to reduce exposure and contain breaches. A DMZ allows organizations to host public services such as web servers while preventing unsolicited direct access to internal application and database tiers. This aligns with long-established best practices from network security architecture guidance, including layered defense and segmentation principles described by organizations such as NIST. Controls like MFA, antivirus, and encryption are valuable, but they do not directly satisfy the requirement to isolate public-facing services and reduce lateral movement risk as effectively as a DMZ with tightly controlled firewall policies.

  • A. Correct.

    Correct. A screened subnet, commonly called a DMZ, is specifically designed to isolate internet-facing systems from the internal network. By placing the public web server in the DMZ and tightly controlling allowed connections to internal application or database servers through firewalls, the organization reduces the attack surface and limits the ability of an attacker to pivot deeper into the enterprise if the web server is compromised. This is a standard network segmentation and boundary protection mitigation technique.

  • B. Incorrect.

    Incorrect. Full-disk encryption protects data at rest if a system is lost, stolen, or decommissioned improperly. It does not meaningfully prevent an attacker who has already compromised a running web server from attempting lateral movement across the network. Someone might choose this because encryption is an important security control, but it does not address network isolation in this scenario.

  • C. Incorrect.

    Incorrect. Multifactor authentication is a strong control for protecting administrative access and reducing account compromise risk. However, it does not by itself isolate a public-facing server from the internal network or limit attacker movement after a host compromise. It is a useful complementary control, but not the best mitigation for the stated requirement.

  • D. Incorrect.

    Incorrect. Host-based antivirus can help detect or block some malware on an endpoint or server, but it does not provide the architectural separation needed to keep internet-exposed systems from directly exposing the internal network. This option addresses endpoint protection, not segmentation or controlled access paths.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam