SY0-701 exam dumps

SY0-701 practice question 198 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 198

Select 2Infrastructure considerations: Device placement , Security zones , Attack surface , Connectivity , Failure modes (Fail-open , Fail-closed )

A healthcare company is redesigning its network after a recent outage exposed both security and availability gaps. The company hosts a public patient portal, an internal electronic medical records (EMR) system, and badge-controlled doors for a medication storage room. During the outage, the internet-facing web server was on the same subnet as internal application servers, and a firewall software crash temporarily allowed unrestricted traffic between network segments. Separately, the badge system stopped locking doors when its controller lost power, creating a safety and compliance concern. Which TWO changes best reduce attack surface and enforce appropriate failure behavior?

  1. A

    Move the public patient portal to a DMZ separated from the internal EMR environment by internal filtering controls

  2. B

    Configure the interzone firewall to fail-open so clinical traffic can continue flowing during any firewall software crash

  3. C

    Place the badge-controlled medication room doors in a fail-closed configuration so loss of controller power keeps the doors locked

  4. D

    Connect the public web server directly to the same security zone as the EMR database to reduce latency and simplify routing

  5. E

    Replace network segmentation with host-based antivirus on all servers because endpoint protection reduces the need for security zones

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are to place the public portal in a DMZ and to configure the medication room doors for fail-closed operation. These choices apply core Security+ infrastructure concepts: device placement, security zones, attack surface reduction, connectivity control, and appropriate failure modes. Public-facing systems should be isolated from sensitive internal systems using segmented zones and tightly defined traffic flows. This aligns with common guidance from NIST and industry best practices on network segmentation and defense in depth, such as NIST SP 800-41 for firewall policy concepts and NIST SP 800-53 controls related to boundary protection. For failure modes, the secure default depends on the business and safety requirement. Protecting controlled medication storage generally requires fail-closed behavior to prevent unauthorized access during outages, whereas some life-safety systems may intentionally use fail-open behavior for emergency egress. The scenario tests the ability to match placement and failure design decisions to real operational risks rather than relying on a one-size-fits-all rule.

  • A. Correct.

    Correct. Placing the public-facing patient portal in a DMZ reduces exposure of the internal network and is a standard design approach for internet-accessible services. The DMZ creates a separate security zone for systems that must communicate with untrusted networks, while internal filtering or firewall rules can tightly control traffic from the portal to internal application components. This reduces attack surface and limits the blast radius if the public server is compromised.

  • B. Incorrect.

    Incorrect. Configuring an interzone firewall to fail-open would prioritize connectivity over security by allowing traffic to pass if the firewall fails. In this scenario, a prior crash already allowed unrestricted traffic between segments, which is exactly the problem the organization wants to prevent. For segmentation boundaries protecting sensitive systems such as EMR environments, fail-closed behavior is generally preferred so traffic is denied if the control point fails.

  • C. Correct.

    Correct. For a medication storage room, loss of power should not cause the door to unlock. A fail-closed configuration preserves the secure state when the controller loses power or fails, which aligns with the stated compliance and safety concern about unauthorized access to controlled substances. This is an example of selecting the proper failure mode based on the asset being protected.

  • D. Incorrect.

    Incorrect. Putting a public web server in the same security zone as the EMR database increases risk by removing an important segmentation boundary. Although it may reduce latency or simplify routing, it significantly expands the attack surface of the internal environment and violates the principle of placing internet-facing systems in a separate zone.

  • E. Incorrect.

    Incorrect. Host-based antivirus is useful, but it does not replace network segmentation. Security zones limit lateral movement, constrain communication paths, and reduce the impact of compromise in ways that endpoint protection alone cannot. This option reflects a common misconception that a single control can substitute for layered defenses.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam