exam questions

Exam 350-201 All Questions

View all questions & answers for the 350-201 exam

Exam 350-201 topic 1 question 10 discussion

Actual exam question from Cisco's 350-201
Question #: 10
Topic #: 1
[All 350-201 Questions]


Refer to the exhibit. Which two steps mitigate attacks on the webserver from the Internet? (Choose two.)

  • A. Create an ACL on the firewall to allow only TLS 1.3
  • B. Implement a reverse server in the DMZ network
  • C. Create an ACL on the firewall to allow only external connections
  • D. Move the webserver to the internal network
  • E. Move the webserver to the external network
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
archbbo
1 month, 3 weeks ago
Selected Answer: BD
how to stop attacks from internet...1 get it off the internet, so move to intranet..
upvoted 1 times
...
marceus
2 months, 3 weeks ago
Selected Answer: BD
ChatGPT: Implementing a reverse server in the DMZ network (Option B): This helps to shield the internal network from direct exposure to the internet. The reverse server acts as an intermediary between the internal web server and external users, reducing the risk of attacks reaching sensitive internal resources. Moving the web server to the external network (Option E): By placing the web server on the external network (like a demilitarized zone, DMZ), it is isolated from the internal network and better protected from attacks aimed at internal systems.
upvoted 1 times
...
DrVoIP
8 months, 3 weeks ago
The two steps that mitigate attacks on the webserver from the Internet are: A. Create an ACL on the firewall to allow only TLS 1.3: Transport Layer Security (TLS) is a protocol that provides secure communication between web servers and clients over the internet. By creating an Access Control List (ACL) on the firewall to allow only TLS 1.3, the web server can be configured to only accept secure connections from clients. This helps to protect against attacks that try to intercept or eavesdrop on communications. B. Implement a reverse server in the DMZ network: A reverse proxy server acts as an intermediary between the internet and the web server. It receives all incoming traffic and then forwards it to the web server. By implementing a reverse server in the DMZ network, the web server can be protected from direct exposure to the internet. The reverse proxy server can perform functions such as filtering traffic, caching data, and providing an additional layer of security by masking the web server's IP address.
upvoted 1 times
...
TOLU1985
1 year, 1 month ago
Selected Answer: AB
Create an ACL on the firewall to allow only TLS 1.3 Implement a proxy server in the DMZ network not sure why they mentioned reverse server... AB is correct
upvoted 1 times
...
kyle942
1 year, 1 month ago
https://resources.infosecinstitute.com/topic/what-is-enumeration/ Enumeration is defined as a process which establishes an active connection to the target hosts to discover potential attack vectors in the system, and the same can be used for further exploitation of the system.
upvoted 1 times
TOLU1985
1 year, 1 month ago
how it related to question? are you bot?
upvoted 1 times
...
...
jaciro11
1 year, 2 months ago
Selected Answer: AB
A and B
upvoted 1 times
...
AlphaOne1
1 year, 4 months ago
You cant use an ACL on a firewall to force TLS 1.3. Thats not a thing and FirePower doesnt support TLS 1.3
upvoted 1 times
...
CiscoTester
1 year, 11 months ago
Only allowing TLS 1.3 can mitigate attacks, the proxy server can also help. C might cause issues for internal users, and D doen't do anything to mitigate attacks. Ans is: A.B.
upvoted 4 times
chongchangchi
1 year, 7 months ago
Is there a way to configure the firewall that can only accept TLS 1.3? by allowing the TLS 1.3 only on a load balancer might cause an issue as well.
upvoted 1 times
jaciro11
1 year, 2 months ago
Yes Its possible https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/getting_started_with_ssl_rules.html
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago