SY0-701 exam dumps

SY0-701 practice question 204 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 204

Single answer

A company hosts a customer-facing web application behind a load balancer in its DMZ. Security analysts discover that attackers are sending crafted HTTP requests that attempt SQL injection against the application. Management wants a solution that can automatically detect and stop these malicious requests before they reach the web servers, without requiring code changes to the application. Which network appliance would BEST meet this requirement?

  1. A

    Deploy a network-based IPS inline between the internet edge and the web application segment

  2. B

    Require administrators to connect through a jump server before accessing the web application servers

  3. C

    Implement a proxy server to cache inbound web content before it reaches the application

  4. D

    Add additional sensors to collect copies of traffic for later security analysis

Show answer and explanation

Correct answer: A

Explanation

The key phrase in the scenario is 'automatically detect and stop these malicious requests before they reach the web servers.' That requirement points to an intrusion prevention system, not an intrusion detection system or passive sensor. An IPS is deployed inline so it can inspect packets and sessions and take preventive action such as dropping traffic, resetting connections, or blocking known attack signatures. By contrast, IDS and sensors are generally detective controls that provide alerting and visibility but do not block traffic themselves. A jump server is intended for administrative access control, not protection of public application traffic. A proxy server may sit between clients and servers, but unless the question explicitly describes a security-capable reverse proxy or web application firewall, the best Security+ answer for inline detection and prevention is an IPS. This aligns with common security architecture guidance, including NIST concepts distinguishing detective controls from preventive controls and vendor documentation describing IPS as an inline blocking technology.

  • A. Correct.

    Correct. A network-based intrusion prevention system (IPS) is designed to inspect traffic inline and can actively block malicious requests, such as known SQL injection patterns, before they reach the protected servers. This directly satisfies the requirement to both detect and stop attacks in real time without modifying the application itself.

  • B. Incorrect.

    Incorrect. A jump server is used to control and secure administrative access to internal systems, typically by serving as a hardened intermediary for remote management. It does not inspect or block customer HTTP requests to a public web application, so it would not mitigate SQL injection attempts from external attackers.

  • C. Incorrect.

    Incorrect. A proxy server can intermediate requests, enforce policy, or cache content depending on its role, but a generic proxy's primary purpose is not inline attack prevention. While some specialized reverse proxies may provide security features, the best answer in this scenario is an IPS because the requirement is specifically to detect and automatically block malicious traffic before it reaches the servers.

  • D. Incorrect.

    Incorrect. Sensors are commonly used for monitoring and visibility, often feeding data to IDS, SIEM, or other analysis platforms. However, sensors alone generally observe and report activity rather than actively prevent malicious traffic. They would help with detection and forensic review, but not with stopping the attack in real time.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam