SY0-701 exam dumps

SY0-701 practice question 201 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 201

Single answerFirewall types: Web application firewall (WAF) , Unified threat management (UTM) , Next-generation firewall (NGFW) , Layer 4/Layer 7

A retail company hosts an Internet-facing e-commerce application that recently experienced several attempts to exploit SQL injection and cross-site scripting vulnerabilities in its checkout pages. The security team also wants better visibility into encrypted web traffic and the ability to block risky applications at the perimeter. However, they do not want to replace the specialized control that best protects the web application itself. Which solution should the company deploy at the perimeter while keeping the most appropriate existing or additional control in front of the web application?

  1. A

    Deploy a next-generation firewall (NGFW) at the perimeter and keep or add a web application firewall (WAF) in front of the e-commerce application

  2. B

    Deploy a layer 4 firewall at the perimeter and remove any WAF because port-based filtering is sufficient for web attacks

  3. C

    Deploy a unified threat management (UTM) appliance at the perimeter and use it as a complete replacement for application-specific web protections

  4. D

    Deploy a layer 7 stateful packet filter at the perimeter and rely on it alone to stop SQL injection in the application code

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy an NGFW at the perimeter and keep or add a WAF in front of the e-commerce application. This reflects defense in depth and proper matching of controls to threats. NGFWs extend traditional firewall capabilities with features such as application awareness, integrated intrusion prevention, and often SSL/TLS inspection support, making them appropriate for perimeter enforcement and visibility. WAFs are purpose-built to protect web applications by inspecting HTTP/HTTPS traffic for attacks such as SQL injection, cross-site scripting, and other OWASP Top 10-style threats. By contrast, layer 4 firewalls focus on ports and protocols and are not sufficient for application-layer web attacks. UTM platforms provide all-in-one security capabilities, but on Security+ questions, the most appropriate answer typically aligns the control to the threat: WAF for web application attacks, NGFW for advanced perimeter control. This is consistent with common industry guidance from NIST and OWASP, which emphasize layered defenses and application-specific protections for Internet-facing web applications.

  • A. Correct.

    Correct. An NGFW is well suited for perimeter deployment when the organization needs application awareness, deeper inspection, and visibility into traffic, including capabilities commonly associated with controlling applications and inspecting encrypted traffic depending on configuration and licensing. A WAF remains the best specialized control for protecting web applications against attacks such as SQL injection and cross-site scripting because it understands HTTP/HTTPS requests and common web attack patterns. This layered approach matches real-world best practice: use an NGFW for broad network/perimeter security and a WAF for application-layer web protection.

  • B. Incorrect.

    Incorrect. A layer 4 firewall primarily makes decisions based on IP addresses, ports, and protocols, which is not sufficient to identify or stop application-layer attacks such as SQL injection or cross-site scripting. Removing a WAF would eliminate the control most specifically designed to inspect HTTP/HTTPS payloads for malicious web requests. This option reflects the misconception that transport-layer filtering can adequately protect modern web applications.

  • C. Incorrect.

    Incorrect. A UTM appliance can consolidate multiple security functions into one platform and may be appropriate for some environments, especially smaller organizations, but it is not the best answer here because the scenario explicitly calls for maintaining the specialized control best suited to protect the web application itself. Replacing application-specific web protections with only a UTM introduces risk because a dedicated WAF provides focused defenses for web-layer attacks that perimeter consolidation alone may not address with the same depth.

  • D. Incorrect.

    Incorrect. This option mixes concepts inaccurately. Layer 7 inspection can provide more context than layer 4, but simply relying on a perimeter device alone is not the most appropriate defense against SQL injection in a web application. A WAF is specifically designed to analyze and filter HTTP/HTTPS requests for malicious patterns targeting web applications. The misconception here is that any device with some application-layer awareness can fully replace a dedicated WAF.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam