exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 66 discussion

Actual exam question from CompTIA's SY0-701
Question #: 66
Topic #: 1
[All SY0-701 Questions]

Which of the following has been implemented when a host-based firewall on a legacy Linux system allows connections from only specific internal IP addresses?

  • A. Compensating control
  • B. Network segmentation
  • C. Transfer of risk
  • D. SNMP traps
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
shady23
Highly Voted 11 months, 3 weeks ago
Selected Answer: A
A. Compensating control w, the keyword in the question is "legacy". Suppose that you have a legacy Linux server which is not compatible with those network-based firewalls, routers and multi-layer switches which is preventing you not just from building VLANs (Network Segmentation), but also from applying white-listing ACL technique against malicious IP addresses. So, what you're going to do is you are going to use host-based firewalls as a compensation for network appliances to be able to accomplish the similar end-result
upvoted 29 times
Grouthorax
8 months, 1 week ago
Appreciate your explanation
upvoted 4 times
...
...
Mehsotopes
Highly Voted 11 months, 3 weeks ago
Selected Answer: A
It is not mentioned that internal IP addresses have been separated from other network IP addresses, but that the host-based firewall is only allowed to communicate with, & protect specific internal IP addresses, this would compensate for threats by mitigating possible attack surfaces that those internal addresses might be vulnerable to from OUTSIDE the network.
upvoted 12 times
Yoez
11 months, 3 weeks ago
I agree with you
upvoted 1 times
...
...
Chidazz
Most Recent 3 months ago
Selected Answer: A
The correct answer is: A. Compensating control Explanation: A compensating control is a security measure implemented to meet security requirements when the primary control is not feasible due to technical or business constraints. In this case, since the system is a legacy Linux system, it might not support modern security features like centralized firewall management. Instead, a host-based firewall is used to restrict access to specific internal IP addresses, serving as an alternative security control. B. Network segmentation refers to dividing a network into separate segments to enhance security and performance, but it is not directly related to a host-based firewall rule. C. Transfer of risk involves shifting risk to another entity, such as purchasing cybersecurity insurance, which is not relevant here. D. SNMP traps are notifications sent from network devices for monitoring and alerting, which also do not apply in this context.
upvoted 1 times
...
Etc_Shadow28000
6 months, 4 weeks ago
Selected Answer: A
A. Compensating control A compensating control is a security measure that is put in place to satisfy the requirements of a security policy or standard when the primary control cannot be implemented. In this case, the host-based firewall on a legacy Linux system allowing connections from only specific internal IP addresses serves as a compensating control to protect the system by limiting access to trusted sources. Therefore, the correct answer is: A. Compensating control
upvoted 4 times
...
dbrowndiver
9 months ago
Selected Answer: A
The implementation of a host-based firewall to restrict access is a compensating control because it mitigates the risks associated with potential vulnerabilities in a legacy system by providing an additional layer of protection.
upvoted 2 times
...
f26ddcd
11 months ago
Selected Answer: A
Compensating control
upvoted 1 times
...
MAKOhunter33333333
11 months, 2 weeks ago
Selected Answer: A
Whenever there is legacy mentioned it is 99% always going to be compensating controls or compensation.
upvoted 3 times
...
AutoroTink
11 months, 2 weeks ago
Selected Answer: B
In the context of the question, which involves a host-based firewall on a legacy Linux system allowing connections from only specific internal IP addresses, the primary goal is to enhance security by limiting access. This is a direct control measure rather than a compensating one. The firewall is not compensating for the inability to implement another control; it is the control itself, enforcing access restrictions based on IP addresses. Configuring the firewall to only allow connections to specific IP addresses, it is segmenting its network.
upvoted 3 times
...
shady23
11 months, 3 weeks ago
Selected Answer: A
A. Compensating control
upvoted 1 times
...
[Removed]
11 months, 3 weeks ago
Answer B.
upvoted 2 times
...
e5c1bb5
11 months, 3 weeks ago
Selected Answer: B
logical network segmentation includes ACL implementation to allow or dissallow specific IP addresses to communicate with a particular device.
upvoted 1 times
...
Punjistetics
11 months, 3 weeks ago
B. Network segmentation. Network segmentation involves dividing a computer network into smaller, isolated networks to improve security and reduce the impact of potential security breaches. By configuring the host-based firewall to allow connections only from specific internal IP addresses, the system is effectively segmenting the network to limit communication to authorized entities, thus enhancing security. Options such as compensating control (A), transfer of risk (C), and SNMP traps (D) do not accurately describe the scenario of restricting connections to specific internal IP addresses through a host-based firewall
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago