SY0-701 exam dumps

SY0-701 practice question 171 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 171

Single answerScalability

A company is migrating its customer portal to a cloud-hosted environment. During seasonal sales, the portal experiences large spikes in legitimate traffic that have previously caused slowdowns and outages. The security team must ensure the application remains available during these spikes while also maintaining consistent security controls across all additional servers that may be brought online automatically. Which solution BEST addresses these requirements?

  1. A

    Deploy the application behind a load balancer and place the web servers in an auto-scaling group that uses a hardened, standardized image for new instances

  2. B

    Increase the CPU and memory on a single web server and disable change management during peak periods so administrators can adjust settings quickly

  3. C

    Require all users to connect through a site-to-site VPN during sales events so traffic can be inspected before reaching the portal

  4. D

    Move the database to an isolated subnet and manually provision extra web servers after administrators confirm performance issues

Show answer and explanation

Correct answer: A

Explanation

The best answer is the load balancer with auto-scaling and hardened images because it combines elasticity, availability, and consistent security. In Security+, scalability often involves designing systems that can handle increased demand without sacrificing security controls. Horizontal scaling through load balancing and auto-scaling is generally preferred for internet-facing applications because it improves fault tolerance and supports rapid response to changing traffic levels. Using standardized hardened images or templates ensures each new instance inherits approved configurations, reducing configuration drift and supporting secure provisioning. This is consistent with common cloud security and operations guidance such as NIST recommendations for secure configuration baselines, configuration management, and availability-focused architecture. The other options either fail to scale effectively, weaken security governance, or introduce controls that do not fit the business scenario.

  • A. Correct.

    Correct. This approach addresses both scalability and security. A load balancer distributes traffic across multiple servers, improving availability and performance during traffic spikes. Auto-scaling allows capacity to increase and decrease dynamically based on demand, which is a core scalability concept. Using a hardened, standardized image ensures each newly deployed instance has consistent security baselines, patches, and configuration settings. This aligns with security best practices such as secure baselines, configuration management, and immutable deployment patterns.

  • B. Incorrect.

    Incorrect. Increasing resources on a single server is vertical scaling, which has limits and creates a single point of failure. It does not provide the resilience or elasticity needed for major traffic spikes. Disabling change management is also a poor security practice because it increases the risk of misconfiguration and unauthorized changes during critical periods.

  • C. Incorrect.

    Incorrect. Requiring all portal users to connect through a site-to-site VPN is impractical for public customer access and would likely reduce availability rather than improve it. While traffic inspection is important, this option does not solve the need for scalable web capacity and introduces unnecessary complexity for external users.

  • D. Incorrect.

    Incorrect. Isolating the database in a subnet can be a good security control, but it does not by itself address frontend scalability. Manually provisioning additional web servers is slower and less reliable than automated scaling, especially during sudden demand spikes. This option also does not ensure new servers are deployed with consistent security configurations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam