How to Protect Business Applications from Data Exfiltration Attacks?

An organization purchased a critical business application containing sensitive data. The organization would like to ensure that the application is not exploited by common data exfiltration attacks. Which of the following approaches would best help to fulfill this requirement?

  1. URL scanning
  2. WAF Source Reference Answer
  3. Reverse proxy
  4. NAC

Community Votes

B
81%
D
19%

81% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to align the attack surface (application-layer data theft) with the appropriate defense tool, while the common trap involves misapplying network access controls to solve a payload-level problem.

This question evaluates knowledge of application-layer defenses against data exfiltration, with the community overwhelmingly selecting a Web Application Firewall (WAF) as the optimal protective measure. Candidates must correctly differentiate between network-edge controls and dedicated application security gateways.

Many candidates incorrectly select NAC (Network Access Control), reasoning that restricting who or what can connect to the application will stop data theft. However, NAC enforces compliance policies at the network boundary and cannot inspect, analyze, or block malicious HTTP/HTTPS payloads or API requests where actual exfiltration takes place.

Community Discussion (5 comments)

chasingsummer 👍 7 Selected: B
A WAF is specifically designed to protect web applications from a variety of attacks, including data exfiltration attempts.
9149f41 👍 3 Selected: B
WAF is more about application security. NAC is more about network security. The question says an application with sensitive data, so it must WAF.
Fourgehan 👍 3 Selected: B
The best approach to fulfill the requirement of preventing data exfiltration attacks on a critical business application is B. WAF (Web Application Firewall). A WAF provides targeted protection against various web-based threats, including those that could lead to data exfiltration, making it the most effective choice among the options listed
9ef4a35 👍 1
A WAF is the most appropriate solution to protect the organization's critical business application from common data exfiltration attacks by filtering and monitoring application traffic
jacobtriestech 👍 3 Selected: D
A Network Access Control (NAC) solution would be the most effective approach to protect the critical business application. NAC can enforce strict access policies, ensuring that only authorized devices and users can access the application. By implementing NAC, the organization can significantly reduce the risk of data exfiltration attacks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Defense Mechanism

The scenario explicitly mentions protecting a critical business application from data exfiltration attacks. In cybersecurity architecture, data exfiltration through web apps typically occurs via compromised APIs, SQL injection, or malicious form submissions. A Web Application Firewall (WAF) operates at Layer 7 (Application Layer) and is specifically engineered to inspect incoming and outgoing web traffic for malicious patterns, blocking exploit attempts before they reach the backend database or server.

Why Option B is Correct

As highlighted by multiple community experts, a WAF provides targeted, protocol-aware protection for web-facing applications. It utilizes signature-based detection, behavioral analysis, and rule sets (like OWASP CRS) to intercept and drop requests attempting to steal or leak sensitive data. This directly fulfills the requirement of preventing exploitation through common exfiltration vectors.

Why Other Options Are Incorrect

URL scanning (Option A) primarily analyzes links for malware or phishing indicators during browsing or email attachment inspection; it does not actively filter live application traffic. A reverse proxy (Option C) handles request routing, load balancing, and SSL termination, but lacks built-in intrusion prevention or payload inspection capabilities unless explicitly paired with a WAF module. NAC (Option D), often chosen due to its strong access control features, operates at Layers 2/3 to verify device posture and authenticate users before granting network connectivity. As noted in the community discussions, while NAC reduces unauthorized network access, it cannot see inside encrypted HTTPS streams or parse application logic to stop active data theft once a connection is established.

Official Reference

Exam Strategy

When an exam question specifies an 'application' or 'web service' facing external threats, immediately prioritize Layer 7 controls like WAFs, API gateways, or runtime application self-protection (RASP). Avoid selecting network-level tools like NAC or traditional firewalls unless the scenario explicitly mentions device compliance, port access, or subnet segmentation.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide