SY0-701 exam dumps

SY0-701 practice question 318 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 318

Single answerFirewall: Rules , Access lists , Ports/protocols , Screened subnets

A company hosts a public web application in a screened subnet (DMZ). The web server must be reachable from the internet over HTTPS, and it must send queries to an internal database server on TCP 1433. Security policy requires that no direct internet access to the internal network be allowed, and all other unsolicited traffic should be blocked. Which firewall rule set BEST meets these requirements?

  1. A

    Allow Any from Internet to Internal Network on TCP 443 and TCP 1433; deny all other traffic

  2. B

    Allow TCP 443 from Internet to DMZ web server; allow TCP 1433 from DMZ web server to internal database server; deny Internet to Internal Network; deny all other unsolicited traffic

  3. C

    Allow TCP 443 and TCP 1433 from Internet to DMZ web server; allow any traffic from DMZ to Internal Network; deny all other traffic

  4. D

    Allow TCP 443 from Internet to Internal database server; allow TCP 1433 from Internal database server to DMZ web server; deny all other traffic

Show answer and explanation

Correct answer: B

Explanation

In a screened subnet architecture, public-facing services such as web servers are placed in a DMZ to reduce the risk of exposing internal systems directly to untrusted networks. The best-practice firewall design is to allow only required inbound traffic from the internet to the DMZ host, then allow only narrowly defined traffic from the DMZ to specific internal systems as needed. Here, that means permitting HTTPS on TCP 443 from the internet to the DMZ web server and permitting SQL traffic on TCP 1433 only from the DMZ web server to the internal database server. Access control lists and firewall rules should be as specific as possible by source, destination, port, and protocol, while ending with an implicit or explicit deny for all other unauthorized traffic. This aligns with common firewall hardening guidance and network segmentation best practices described by organizations such as NIST, including the principle of least privilege and layered defense.

  • A. Incorrect.

    Incorrect. This rule set violates the requirement to prevent direct internet access to the internal network. Allowing inbound TCP 443 and TCP 1433 from the internet to internal hosts exposes the internal network directly and bypasses the purpose of a screened subnet. A DMZ is specifically designed to isolate public-facing systems from internal assets.

  • B. Correct.

    Correct. This rule set follows the principle of least privilege and proper screened subnet design. It permits only HTTPS (TCP 443) from the internet to the public-facing web server in the DMZ, allows only the required database communication (TCP 1433) from that DMZ web server to the specific internal database server, explicitly blocks direct Internet-to-Internal access, and denies other unsolicited traffic. This is the standard approach for segmenting public services while protecting internal systems.

  • C. Incorrect.

    Incorrect. Although allowing TCP 443 from the internet to the DMZ web server is appropriate, allowing TCP 1433 from the internet to the DMZ web server is unnecessary for a public web application and exposes a database-related service externally. In addition, allowing any traffic from the DMZ to the internal network is overly permissive and violates least privilege. DMZ-to-internal access should be tightly restricted to only required hosts, ports, and protocols.

  • D. Incorrect.

    Incorrect. This rule set places the public-facing HTTPS service on the internal database server instead of the DMZ web server, which does not match the scenario and would expose an internal system unnecessarily. It also reverses the intended database communication flow. The web server in the DMZ should initiate connections to the internal database server on the required port, not the other way around.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam