Troubleshooting Application Access to Internal Resources
When a newly developed application was tested, a specific internal resource was unable to be accessed. Which of the following should be done to ensure the application works correctly?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between application logic errors and network-level access restrictions, with the trap being confusion over protocols or coding practices.
When an application fails to access a specific internal resource during testing, the issue typically stems from restrictive access policies. This page establishes that modifying allow/deny lists is the correct remediation step.
Many learners choose D (Utilize standard network protocols) because they assume connectivity issues are always protocol-related, ignoring the explicit mention of 'specific' resources which implies access control.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario describes a situation where a newly developed application cannot reach a specific internal resource. In the context of CompTIA Security+ (SY0-601), this points directly to an access control issue rather than a development or transport layer problem. The most effective way to grant necessary access while maintaining security is to update the allow/deny list (such as an ACL, firewall rule, or application-specific permission set) to explicitly permit the application to communicate with that resource.Why the Other Options Are Wrong
Option B (Secure coding) addresses vulnerabilities within the code itself, not external access permissions. Option C (Sandbox environment) is used for isolation and testing safety, but it does not solve the problem of accessing a production internal resource; in fact, sandboxes often restrict such access by design. Option D (Standard network protocols) is irrelevant because the issue is likely not about the protocol type (e.g., HTTP vs FTP) but rather whether the application is authorized to use the network path to that specific resource.Community Comment Notes
The community widely agrees on Option A, though many express frustration with the question's phrasing. As user fryderyk noted, "was unable to be accessed" could imply various reasons, but the consensus leans towards access denial. User dfc6822 correctly reasoned that modifying the allow/deny list is necessary to ensure the application has the required permissions. Another commenter, spearous, initially chose D but conceded that from a Security+ perspective, access control (A) is the intended answer.Exam Strategy
Focus on keywords like 'specific resource' and 'unable to be accessed' to identify access control problems. Always look for configuration changes (like lists or rules) before assuming fundamental architectural or coding flaws.
Frequently Asked Questions
Why isn't using standard network protocols the answer?
The issue is access to a 'specific' resource, implying authorization failure, not a transport layer compatibility issue.
Does this apply to firewalls only?
No, 'allow/deny list' is a general term for access controls including ACLs, firewall rules, and application-level permissions.