Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SY0-601 topic 1 question 365 discussion

Actual exam question from CompTIA's SY0-601
Question #: 365
Topic #: 1
[All SY0-601 Questions]

The marketing department at a retail company wants to publish an internal website to the internet so it is reachable by a limited number of specific, external service providers in a secure manner. Which of the following configurations would be BEST to fulfil this requirement?

  • A. NAC
  • B. ACL
  • C. WAF
  • D. NAT
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ramesh2022
Highly Voted 1 year, 2 months ago
Selected Answer: B
The best configuration to fulfil this requirement is B. ACL (Access Control List). An Access Control List can be used to restrict access to external service providers based on their IP addresses, enabling a secure method of publishing the internal website to the internet.
upvoted 28 times
milkyway_615
1 year, 1 month ago
I agree ACL is the best answer
upvoted 3 times
...
vitasaia
3 months ago
It works but it's not very practical. You need to ask the service providers to share their IPs. What if they don't have static IPs?
upvoted 1 times
...
...
BigSecurityGuy
Highly Voted 5 months, 2 weeks ago
I miss stoneface
upvoted 12 times
Cloudninja117
5 months, 1 week ago
Same here, also I wonder if he ever passed.
upvoted 5 times
...
Teacher2Cyber
5 months ago
And applebeeswaitress and proctorguy
upvoted 8 times
Theoreign
3 months, 4 weeks ago
And rodwave
upvoted 4 times
...
...
...
AspiringNerd
Most Recent 1 week, 1 day ago
Selected Answer: C
The BEST configuration to fulfill the requirement of publishing an internal website to the internet, reachable by a limited number of specific, external service providers in a secure manner, would be: C. WAF (Web Application Firewall). A WAF is specifically designed to protect web applications from a variety of attacks, including SQL injection, cross-site scripting (XSS), and other common web-based threats. By deploying a WAF in front of the internal website, the marketing department can enforce access controls, inspect and filter incoming web traffic, and apply security policies to ensure that only authorized external service providers can access the website. While ACLs (Access Control Lists) could be used to restrict access to specific IP addresses or ranges, they typically operate at a lower level of the network stack and may not provide the same level of application-layer protection as a WAF.
upvoted 1 times
AspiringNerd
1 week, 1 day ago
NAC (Network Access Control) is used to enforce security policies for devices connecting to a network, but it may not be directly applicable to securing a specific web application published to the internet. NAT (Network Address Translation) is a technique used to map private IP addresses to public IP addresses and vice versa, but it does not provide the necessary application-layer security controls required to protect a web application from attacks and unauthorized access. Therefore, a WAF would be the most appropriate and effective configuration for securely publishing the internal website to the internet while restricting access to specific external service providers.
upvoted 1 times
...
...
shady23
1 week, 4 days ago
Selected Answer: C
WAF (Web Application Firewall)
upvoted 1 times
...
BD69
1 month ago
Selected Answer: C
I had to go with WAF on this one. WAF is a firewall, and has ACL built into it. The only problem I have with this question is it asks for "configurations", not device, so maybe I'm wrong here. ACL is a configuration, WAF is a device. UGH!!!
upvoted 2 times
...
Paula77
2 months, 1 week ago
Selected Answer: B
The question asks for the “BEST” configuration not best technology. Whilst ACL is a capability of a WAF it is also the best configuration.
upvoted 2 times
...
NoConfusion
2 months, 1 week ago
Selected Answer: C
I initially accepted that this was ACL, but after going through all 800+ questions, studying comptia content, and coming back to this one, it's definitely WAF.
upvoted 3 times
...
eddy72
2 months, 2 weeks ago
Selected Answer: D
A VPN (virtual private network) is a secure tunnel used to encrypt traffic and prevent unauthorized access to the internal network. It is a secure way to extend a private network across public networks, such as the Internet, and can be used to allow remote users to securely access resources on the internal network. Additionally, a VPN can be used to prevent malicious traffic from entering the internal network.
upvoted 1 times
...
GeekSpunk
2 months, 2 weeks ago
Selected Answer: C
WAF is the correct answer
upvoted 1 times
...
memodrums
2 months, 2 weeks ago
Selected Answer: B
ACL is the most logical answer here's why. NAC will be good if the vendors are physically connecting to the network. WAF only protects against web application attacks.
upvoted 1 times
...
kewokil120
2 months, 3 weeks ago
Selected Answer: C
WAF will inspect traffic. ACL and NAT will allow the traffic. WAF is the higher security protocol as it looks at layer 7.
upvoted 1 times
...
vitasaia
3 months ago
Selected Answer: C
Considering practicality and efficiency, it's WAF. ACL using IP doesn't make sense if they use DHCP. Don't use NAC (+ VPN) coz it's not mentioning VPN.
upvoted 1 times
...
[Removed]
3 months ago
"reachable by a limited number of specific". normally WAF but in this case protection by allowing some IP only thus ACL ..
upvoted 1 times
...
johnabayot
3 months ago
Selected Answer: C
C. WAF A WAF can be deployed in front of an internal website to filter and block malicious requests from the internet, while allowing authorized access from specific external service providers. A WAF can also provide encryption, authentication, and logging features to enhance the security of the web application.
upvoted 2 times
...
Benrosan
3 months, 1 week ago
Selected Answer: B
ACL can be configured to allow only relevant IPs.
upvoted 1 times
...
Susan4041
3 months, 2 weeks ago
Selected Answer: C
A Web Application Firewall (WAF) is specifically designed to protect web applications from various security threats, including common web vulnerabilities and attacks. In the context of publishing an internal website to the internet, a WAF can provide an additional layer of security by inspecting and filtering HTTP traffic between a user's browser and the web application.
upvoted 2 times
...
maggie22
3 months, 3 weeks ago
Selected Answer: C
talking about security? WAF is the answer.
upvoted 2 times
edoardottt
3 months, 3 weeks ago
With a WAF you can't declare an allow list. It's B
upvoted 2 times
BD69
1 month ago
It's a firewall, of course you can set allows and blocks.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...