exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 472 discussion

Actual exam question from CompTIA's SY0-701
Question #: 472
Topic #: 1
[All SY0-701 Questions]

A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?

  • A. Anti-malware solutions
  • B. Host-based firewalls
  • C. Intrusion prevention systems
  • D. Network access control
  • E. Network allow list
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pitrix
4 weeks, 1 day ago
Selected Answer: E
E. Network allow list Here’s why: • A network allow list (also known as a whitelist) ensures that only trusted sources or specific IP addresses are allowed to send traffic to the internal network. This approach effectively blocks all untrusted external traffic, which directly prevents malicious packets from entering the network in the first place.
upvoted 1 times
...
Anyio
2 months, 3 weeks ago
Selected Answer: C
C. Intrusion Prevention Systems (IPS) Explanation: An Intrusion Prevention System (IPS) actively monitors network traffic for suspicious patterns or malicious packets and blocks them before they can reach the internal network. IPS is specifically designed to detect and prevent externally crafted malicious packets, making it the most secure and effective solution for this scenario. Other Options: B. Host-based firewalls: While useful for protecting individual devices, they are not sufficient to secure the entire internal network from malicious packets. D. Network access control (NAC): NAC is focused on ensuring that only authorized devices can connect to the network but does not inspect or block malicious packets. E. Network allow list: This approach can restrict access to only known safe sources but is less dynamic and effective against crafted malicious packets compared to IPS.
upvoted 2 times
...
1f2b013
4 months ago
Selected Answer: C
An IPS provides comprehensive protection against malicious network traffic by analyzing and filtering packets before they reach the internal network.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago