SY0-701 exam dumps

SY0-701 practice question 322 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 322

Single answerWeb filter: Agent-based , Centralized proxy , Universal Resource Locator (URL) scanning , Content categorization , Block rules , Reputation

A company has moved to a hybrid work model, and many users now work from home without a VPN connection. The security team must enforce web filtering for all users, whether they are on the corporate network or remote. Requirements include blocking newly registered malicious sites, preventing access to categories such as gambling and adult content, and allowing security staff to quickly update deny rules for specific URLs during an incident. Which solution would BEST meet these requirements?

  1. A

    Deploy an agent-based web filter on endpoints that uses cloud-managed URL scanning, content categorization, reputation checks, and centrally managed block rules

  2. B

    Use a centralized proxy located at headquarters and require filtering only when users are connected to the office network

  3. C

    Rely on the host-based firewall on each laptop to block outbound TCP ports 80 and 443 to suspicious destinations

  4. D

    Implement DNS zone transfers between branch offices so malicious domains can be removed from internal DNS records more quickly

Show answer and explanation

Correct answer: A

Explanation

The best answer is the agent-based web filter because the key design constraint is coverage for remote users who are not connected through the corporate network. In traditional enterprise environments, a centralized proxy can enforce URL filtering, category-based policies, and block rules effectively for on-premises traffic. However, hybrid work has made endpoint-based or cloud-delivered enforcement more important because the control must follow the user. Web filtering solutions commonly evaluate requests using several methods: URL scanning to inspect requested destinations, content categorization to enforce acceptable-use policy, block rules to deny explicitly identified URLs or domains, and reputation services to identify destinations associated with malware, phishing, or recently observed malicious activity. Security best practices from major vendors and enterprise security guidance consistently emphasize matching the control placement to user location and traffic flow. If users are frequently off-network, relying only on a centralized proxy creates blind spots unless all traffic is tunneled back through the organization. Therefore, an agent-based solution with centralized policy management is the most appropriate choice for this scenario.

  • A. Correct.

    Correct. An agent-based web filter is well suited for hybrid and remote users because protection stays with the endpoint even when it is off the corporate network and not using a VPN. Modern endpoint or cloud-delivered web filtering platforms commonly evaluate requests using URL scanning, content categorization, and reputation services, and they allow administrators to push centralized block rules rapidly during an incident. This directly satisfies all stated requirements: off-network enforcement, category blocking, rapid deny-list changes, and protection against malicious or newly suspicious sites.

  • B. Incorrect.

    Incorrect. A centralized proxy is a common web filtering design for users on the corporate network, but by itself it does not protect users who are working remotely without a VPN. The scenario specifically states that many users are off-network, so filtering only when connected to the office would leave a major gap. A candidate might choose this because centralized proxies are strongly associated with URL filtering, but the design does not meet the coverage requirement.

  • C. Incorrect.

    Incorrect. A host-based firewall can control network ports and sometimes destinations, but it is not a practical web filtering solution for this use case. Blocking ports 80 and 443 would also break normal web access rather than selectively block risky URLs or content categories. It does not provide content categorization, reputation-based decisions, or rapid incident-driven URL deny rules in the way a web filter does.

  • D. Incorrect.

    Incorrect. DNS zone transfers are used to replicate DNS data between DNS servers, not to perform endpoint web filtering. Removing entries from internal DNS would not stop users from browsing the internet generally, and it would not provide URL scanning, category enforcement, or reputation-based web access control. Someone might choose this if they confuse DNS security controls with web filtering controls, but it does not address the stated business need.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam