How to Protect Business Applications from Data Exfiltration Attacks?
An organization purchased a critical business application containing sensitive data. The organization would like to ensure that the application is not exploited by common data exfiltration attacks. Which of the following approaches would best help to fulfill this requirement?
Community Votes
81% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to align the attack surface (application-layer data theft) with the appropriate defense tool, while the common trap involves misapplying network access controls to solve a payload-level problem.
This question evaluates knowledge of application-layer defenses against data exfiltration, with the community overwhelmingly selecting a Web Application Firewall (WAF) as the optimal protective measure. Candidates must correctly differentiate between network-edge controls and dedicated application security gateways.
Many candidates incorrectly select NAC (Network Access Control), reasoning that restricting who or what can connect to the application will stop data theft. However, NAC enforces compliance policies at the network boundary and cannot inspect, analyze, or block malicious HTTP/HTTPS payloads or API requests where actual exfiltration takes place.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Defense Mechanism
The scenario explicitly mentions protecting a critical business application from data exfiltration attacks. In cybersecurity architecture, data exfiltration through web apps typically occurs via compromised APIs, SQL injection, or malicious form submissions. A Web Application Firewall (WAF) operates at Layer 7 (Application Layer) and is specifically engineered to inspect incoming and outgoing web traffic for malicious patterns, blocking exploit attempts before they reach the backend database or server.Why Option B is Correct
As highlighted by multiple community experts, a WAF provides targeted, protocol-aware protection for web-facing applications. It utilizes signature-based detection, behavioral analysis, and rule sets (like OWASP CRS) to intercept and drop requests attempting to steal or leak sensitive data. This directly fulfills the requirement of preventing exploitation through common exfiltration vectors.Why Other Options Are Incorrect
URL scanning (Option A) primarily analyzes links for malware or phishing indicators during browsing or email attachment inspection; it does not actively filter live application traffic. A reverse proxy (Option C) handles request routing, load balancing, and SSL termination, but lacks built-in intrusion prevention or payload inspection capabilities unless explicitly paired with a WAF module. NAC (Option D), often chosen due to its strong access control features, operates at Layers 2/3 to verify device posture and authenticate users before granting network connectivity. As noted in the community discussions, while NAC reduces unauthorized network access, it cannot see inside encrypted HTTPS streams or parse application logic to stop active data theft once a connection is established.Official Reference
- https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering_and_Reconnaissance/04-Map_Application_Architecture
- https://www.nist.gov/publications/guidelines-public-web-servers-and-applications-nist-sp-800-44
- https://a.comptia.org/certifications/security
Exam Strategy
When an exam question specifies an 'application' or 'web service' facing external threats, immediately prioritize Layer 7 controls like WAFs, API gateways, or runtime application self-protection (RASP). Avoid selecting network-level tools like NAC or traditional firewalls unless the scenario explicitly mentions device compliance, port access, or subnet segmentation.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →