A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?
E. Network allow list
Here’s why:
• A network allow list (also known as a whitelist) ensures that only trusted sources or specific IP addresses are allowed to send traffic to the internal network. This approach effectively blocks all untrusted external traffic, which directly prevents malicious packets from entering the network in the first place.
C. Intrusion Prevention Systems (IPS)
Explanation:
An Intrusion Prevention System (IPS) actively monitors network traffic for suspicious patterns or malicious packets and blocks them before they can reach the internal network.
IPS is specifically designed to detect and prevent externally crafted malicious packets, making it the most secure and effective solution for this scenario.
Other Options:
B. Host-based firewalls: While useful for protecting individual devices, they are not sufficient to secure the entire internal network from malicious packets.
D. Network access control (NAC): NAC is focused on ensuring that only authorized devices can connect to the network but does not inspect or block malicious packets.
E. Network allow list: This approach can restrict access to only known safe sources but is less dynamic and effective against crafted malicious packets compared to IPS.
An IPS provides comprehensive protection against malicious network traffic by analyzing and filtering packets before they reach the internal network.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.SY0-701 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Pitrix
4 weeks, 1 day agoAnyio
2 months, 3 weeks ago1f2b013
4 months ago