Protecting Internet-Facing Websites from Buffer Overflow Attacks
An organization’s internet-facing website was compromised when an attacker exploited a buffer overflow. Which of the following should the organization deploy to best protect against similar attacks in the future?
Community Votes
78% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between network-level security (NGFW) and application-level security (WAF), with the common trap being the selection of NGFW due to its broader capabilities rather than its specific fit for web application vulnerabilities.
A Web Application Firewall (WAF) is the optimal defense for internet-facing websites against application-layer exploits like buffer overflows, SQL injection, and XSS. The community consensus strongly favors WAF over NGFW because it operates specifically at Layer 7 to inspect HTTP/HTTPS traffic payloads.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Web Application Firewall (WAF) is designed to filter, monitor, and block HTTP traffic to and from a web service, making it the ideal tool for protecting internet-facing websites. It inspects the content of web requests to detect malicious patterns associated with application-layer attacks, including buffer overflows, SQL injections, and cross-site scripting (XSS). Since the compromised asset is specifically an 'internet-facing website,' a WAF provides the necessary granular control over web traffic that general firewalls lack.Why the Other Options Are Wrong
Next-Generation Firewalls (NGFWs) primarily operate at Layers 3 and 4, offering deep packet inspection but often lacking the sophisticated application-layer logic required to parse complex web code for specific vulnerabilities like buffer overflows without significant performance overhead or false positives. TLS (Transport Layer Security) encrypts data in transit but does not inspect payload content for malicious code or exploit attempts. SD-WAN focuses on optimizing wide area network connectivity and path selection, providing no intrinsic security features against application exploits.Community Comment Notes
Comment [3] correctly highlights that while NGFWs have some Layer 7 capabilities, they are designed for broader network protection, whereas WAFs are specialized for web services. Comment [6] raises a valid point about input validation being the root fix, but notes that in the context of immediate deployment options listed, WAF is the best defensive measure among the choices. Several users confused NGFW with WAF, but the consensus confirms that for web-specific attacks, WAF is the standard answer.Official Reference
Exam Strategy
Always identify the specific asset type mentioned in the scenario; if it is a 'website' or 'web application,' prioritize WAF solutions over general network firewalls. Focus on the attack vector: if it involves HTTP/HTTPS payloads (like SQLi or buffer overflows in code), look for application-layer defenses first.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →