SY0-701 exam dumps

SY0-701 practice question 202 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 202

Single answerDevice attribute: Active vs. passive , Inline vs. tap/monitor

A security administrator needs to add a new network security device in front of a public web application that is frequently targeted by malicious requests. Management wants the device to actively stop suspicious traffic before it reaches the servers. However, the administrator is also evaluating a separate monitoring solution for the core switch that must observe traffic without introducing latency or creating a point of failure in the production path. Which combination best meets both requirements?

  1. A

    Deploy an inline active device for the web application, and use a passive monitor connected through a network tap or SPAN port for the core switch

  2. B

    Deploy a passive monitor for the web application, and use an inline active device on the core switch so traffic can be copied for analysis

  3. C

    Deploy inline passive devices in both locations because inline placement does not affect traffic flow

  4. D

    Deploy active tap devices in both locations because taps can block malicious traffic while remaining out of band

Show answer and explanation

Correct answer: A

Explanation

This question tests the difference between active vs. passive and inline vs. monitor/tap deployments. In Security+ terms, an active security device can take action on traffic, while a passive device primarily observes and alerts. Inline devices are placed directly in the network path, which allows enforcement but can introduce latency or availability risk. Tap/monitor deployments are out of band; they receive copied traffic and are commonly used for IDS, packet capture, and network monitoring when visibility is needed without affecting production forwarding. In practice, organizations commonly deploy IPS, firewalls, or WAFs inline when they need prevention, and deploy IDS sensors or analyzers via network taps or SPAN ports when they need detection and visibility. This aligns with common vendor documentation and network security best practices: prevention requires in-path enforcement, while passive monitoring is preferred when minimizing operational impact is the priority.

  • A. Correct.

    Correct. An inline active device sits directly in the traffic path and can inspect and take action, such as blocking or dropping malicious requests before they reach the web application. This matches the requirement to actively stop suspicious traffic. For the core switch monitoring use case, a passive monitor connected through a network tap or a switch SPAN/mirror port can observe traffic without being part of the live forwarding path, which avoids adding latency and reduces the risk of becoming a single point of failure.

  • B. Incorrect.

    Incorrect. A passive monitor for the web application can observe and alert on malicious traffic, but it cannot directly prevent the traffic from reaching the servers because it is not enforcing inline. The second part is also flawed: placing an inline active device at the core switch would insert the tool into the production path, which conflicts with the requirement to avoid added latency and avoid creating a point of failure just for monitoring.

  • C. Incorrect.

    Incorrect. Inline placement means the device is in the traffic path, so it can affect traffic flow, latency, and availability. Calling such devices 'inline passive' is misleading in this context. If a device is truly passive for monitoring, it is typically out of band and receives copied traffic from a tap or mirror port rather than forwarding production traffic itself.

  • D. Incorrect.

    Incorrect. A network tap is generally used to copy traffic for monitoring and analysis; it does not normally block malicious traffic as a security control. The phrase 'active tap devices' combines concepts incorrectly. If the goal is to block traffic, the device must be inline and capable of active enforcement, such as an IPS or WAF deployed in the traffic path.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam