SY0-701 exam dumps

SY0-701 practice question 205 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 205

Single answer

A company hosts a customer-facing web application in a DMZ behind a load balancer. After a recent update, the security team discovers repeated SQL injection attempts coming from multiple external IP addresses. Management wants a solution that can automatically detect and stop these malicious requests before they reach the web servers, while still allowing legitimate traffic to pass. Which network appliance would BEST meet this requirement?

  1. A

    Jump server

  2. B

    Proxy server

  3. C

    Intrusion prevention system (IPS)

  4. D

    Network sensor connected to a monitoring port

Show answer and explanation

Correct answer: C

Explanation

The key phrase in the scenario is that the company wants to automatically detect and stop malicious requests before they reach the web servers. That requirement points to an IPS rather than an IDS or passive sensor. An IDS or network sensor can identify suspicious activity and generate alerts, but it usually does not sit inline to actively block traffic. A jump server serves a very different purpose: securing administrative access. A proxy server can provide request handling and filtering in some architectures, but on Security+ questions, when the requirement is to inspect live traffic and actively prevent attacks such as SQL injection, the best answer is an IPS. This aligns with common security architecture guidance, including NIST concepts around intrusion detection and prevention technologies, where IPS solutions are positioned inline to detect and take action on malicious traffic.

  • A. Incorrect.

    A jump server is used to provide controlled administrative access to internal systems, typically by acting as a hardened intermediary for remote management. It is not designed to inspect and block malicious application traffic such as SQL injection attempts targeting public web servers.

  • B. Incorrect.

    A proxy server can mediate client requests and may provide filtering, caching, or anonymity features depending on the implementation. However, a generic proxy server is not the best answer here because the requirement is specifically to automatically detect and block malicious traffic patterns before they reach the servers. That is the primary role of an IPS.

  • C. Correct.

    An intrusion prevention system (IPS) is correct because it is designed to inspect traffic inline and take preventive action, such as dropping or rejecting malicious packets or sessions. In this scenario, the company needs a control that both detects SQL injection attempts and stops them before they reach the web application, which aligns with IPS functionality.

  • D. Incorrect.

    A network sensor connected to a monitoring port is typically used for visibility, traffic collection, or detection when paired with monitoring tools, but by itself it is generally out-of-band and does not block traffic. This makes it useful for alerting and analysis, not for the required automatic prevention.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam