exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 296 discussion

Actual exam question from CompTIA's SY0-701
Question #: 296
Topic #: 1
[All SY0-701 Questions]

A security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place. Which of the following would be best to set up? (Choose two.)

  • A. NIDS
  • B. Honeypot
  • C. Certificate revocation list
  • D. HIPS
  • E. WAF
  • F. SIEM
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
c7b3ff0
Highly Voted 6 months, 1 week ago
Selected Answer: AE
I'm going A and E. F would be a good thing to implement too, but the questions is asking specifically for advanced network capabilities and a SIEM does a lot more than just that. NIDS and WAF are the network-focused options I think it wants us to choose.
upvoted 5 times
...
9149f41
Most Recent 2 months, 4 weeks ago
Selected Answer: AE
apologies, The question says for web application, so HIPS is not the answer.
upvoted 1 times
...
9149f41
2 months, 4 weeks ago
Selected Answer: DE
Out of all the options, only HIPS and WAF are helpful for prevention. WAF is used for both detection and prevention. The question says Advanced Network Security Capability. To me it is not enough relevant with SIEM or NIDS, as it does not protect the system.
upvoted 2 times
...
fc040c7
2 months, 4 weeks ago
Selected Answer: AE
if we are going off of network security. NIDS will monitor the whole network as opposed to just one host (HIPS). and a WAF protect the web application.
upvoted 1 times
...
ProudFather
4 months, 3 weeks ago
Selected Answer: EF
A Web Application Firewall (WAF) is specifically designed to protect web applications from attacks such as SQL injection, cross-site scripting, and cross-site request forgery. It can filter and block malicious traffic, protecting the web application from vulnerabilities. A Security Information and Event Management (SIEM) system can be used to monitor network traffic and identify potential security threats. By analyzing logs from various sources, including the WAF, the SIEM can detect and respond to attacks in real-time.
upvoted 3 times
...
c7b3ff0
6 months, 1 week ago
Selected Answer: DE
Changing my previous answer. D&E. WAF protects the web application by filtering and monitoring HTTP/HTTPS traffic (port 443 is HTTPS). A HIPS installed on the web application's server will monitor/analyze activity with the ability to detect and prevent exploitation of vulnerabilities.
upvoted 4 times
...
Ty13
7 months ago
Selected Answer: AE
A. NIDS E. WAF They're asking for setting things up. So set up a WAF and then a NIDS - anomalies would alert admins to take action. SIEM is good because it's still collecting data, but it's more about overall data security whereas NIDS is specifically for the network.
upvoted 3 times
...
Szajba123
7 months, 2 weeks ago
Selected Answer: EF
Why: E. WAF (Web Application Firewall): A WAF is specifically designed to protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. It can help prevent attacks such as SQL injection, cross-site scripting (XSS), and other common web-based threats. Setting up a WAF on port 443 (which is used for HTTPS traffic) would directly address risks associated with web application vulnerabilities. F. SIEM (Security Information and Event Management): A SIEM system collects and analyzes security data from across the network, including logs and events from the web application. It provides real-time analysis, helps in detecting anomalies, and assists in responding to potential threats. This would complement the WAF by providing a broader view of security incidents and facilitating incident response.
upvoted 2 times
...
ef5549f
8 months ago
GPT: A & E
upvoted 1 times
...
a4e15bd
8 months, 1 week ago
Selected Answer: DE
Changing my previous answer. I got with D & E. Together these two tools should provide a comprehensive defense securing both the application and the underlying server.
upvoted 3 times
...
cri88
8 months, 1 week ago
Selected Answer: AE
E. WAF (Web Application Firewall) A. NIDS (Network Intrusion Detection System) Explanation: E. WAF (Web Application Firewall): A WAF specifically protects web applications by filtering and monitoring HTTP/HTTPS traffic between a web application and the internet. It can help detect and block attacks targeting the web application, such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities. A. NIDS (Network Intrusion Detection System): NIDS monitors network traffic for suspicious activity and potential threats. Deploying NIDS can help detect malicious activity at the network level, including attempts to exploit vulnerabilities over port 443. These two options would significantly enhance the security of the web application by providing both application-level protection (WAF) and network-level monitoring (NIDS).
upvoted 2 times
...
nyyankee718
8 months, 2 weeks ago
Selected Answer: AE
Could be A and F also? NIDS (Network Intrusion Detection System): This system monitors network traffic for potential malicious activity, including attempts to exploit vulnerabilities in the web application. While it primarily detects rather than prevents, it provides valuable insights into potential threats and alerts the security team
upvoted 3 times
...
mr_reyes
8 months, 2 weeks ago
Doesn't SIEM only monitor and report, not actually prevent? Wouldn't HIPS be more appropriate?
upvoted 3 times
...
a4e15bd
8 months, 2 weeks ago
WAF and SIEM are correct answers.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago