SY0-701 exam dumps

SY0-701 practice question 323 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 323

Single answerWeb filter: Agent-based , Centralized proxy , Universal Resource Locator (URL) scanning , Content categorization , Block rules , Reputation

A company has moved to a hybrid work model, and many employees now work from home or travel frequently. The security team currently uses a centralized web proxy at headquarters to enforce URL filtering and block access to high-risk websites. However, logs show that remote users who are off the corporate VPN can still browse malicious and inappropriate sites directly from their laptops. Management wants the company to enforce web filtering for all users regardless of location, while still using block rules based on URL reputation and content categories such as gambling, malware, and adult content. Which solution would BEST meet this requirement?

  1. A

    Deploy an agent-based web filter on corporate endpoints so policies follow users off-network and can enforce URL scanning, reputation checks, and category-based block rules

  2. B

    Rely on the existing centralized proxy and require users to manually configure their browsers to use it when traveling

  3. C

    Replace the web filter with a network firewall ACL that blocks outbound TCP ports 80 and 443 for remote users

  4. D

    Use DNS round-robin to redirect remote users to the headquarters proxy without installing any endpoint software

Show answer and explanation

Correct answer: A

Explanation

The best answer is the agent-based web filter because the key requirement is enforcement for users regardless of location. Centralized proxies are common for controlling web access on corporate networks, but they are less effective when users are remote and not connected through VPN or other forced-tunneling solutions. Agent-based filtering solves this by enforcing policy on the endpoint itself. In practice, modern web filtering solutions commonly combine URL scanning, content categorization, block rules, and reputation services to decide whether a site should be allowed, warned, or blocked. Security best practices from major enterprise security vendors and secure web gateway guidance consistently emphasize that remote and hybrid workforces require either endpoint-based enforcement or cloud-delivered secure web controls, because on-premises proxies alone do not fully protect off-network devices.

  • A. Correct.

    This is correct. An agent-based web filter is designed to apply web access policies directly on the endpoint, which is especially useful for laptops used outside the corporate network. It can enforce URL scanning, content categorization, block rules, and reputation-based filtering even when users are not connected to the internal network or VPN. This directly addresses the organization's requirement for consistent protection regardless of user location.

  • B. Incorrect.

    This is incorrect. A centralized proxy can be effective for on-network traffic, but it does not reliably protect off-network users unless all traffic is forced through it. Manual browser configuration is error-prone, easy for users to bypass, and does not provide dependable policy enforcement. The misconception is that a proxy alone solves remote-user filtering, but without a mechanism to ensure traffic traverses it, enforcement is inconsistent.

  • C. Incorrect.

    This is incorrect. Blocking ports 80 and 443 would effectively prevent normal web browsing rather than selectively filtering malicious or inappropriate content. It also would not provide URL scanning, category-based controls, or reputation analysis. This distractor reflects a misunderstanding between coarse network-layer blocking and application-aware web filtering.

  • D. Incorrect.

    This is incorrect. DNS round-robin is a load distribution technique and does not transparently force remote web traffic through a corporate proxy. Even if remote users resolved the proxy hostname, they would still need an explicit or transparent method to send traffic to it. This option also does not address endpoint enforcement when users are off-network.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam