What Advanced Network Security Controls Protect a Web App on Port 443?

A security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place. Which of the following would be best to set up? (Choose two.)

  1. NIDS Source Reference Answer
  2. Honeypot
  3. Certificate revocation list
  4. HIPS
  5. WAF Source Reference Answer

Community Votes

AE
63%
DE
37%

63% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the ability to differentiate between host-based and network-based security controls, with the common trap being selecting HIPS instead of NIDS due to confusion over prevention versus detection capabilities.

This question tests selecting appropriate security controls to mitigate risks on a web application's HTTPS traffic. The majority of candidates agree that a WAF and NIDS provide the best combination of application-level filtering and network-wide monitoring.

Many candidates incorrectly choose HIPS and WAF (DE), believing that host-based prevention paired with a WAF offers complete coverage. However, HIPS operates at the endpoint level rather than providing the "advanced network security capabilities" explicitly requested by the scenario.

Community Discussion (15 comments)

c7b3ff0 👍 5 Selected: AE
I'm going A and E. F would be a good thing to implement too, but the questions is asking specifically for advanced network capabilities and a SIEM does a lot more than just that. NIDS and WAF are the network-focused options I think it wants us to choose.
9149f41 👍 1 Selected: AE
apologies, The question says for web application, so HIPS is not the answer.
9149f41 👍 2 Selected: DE
Out of all the options, only HIPS and WAF are helpful for prevention. WAF is used for both detection and prevention. The question says Advanced Network Security Capability. To me it is not enough relevant with SIEM or NIDS, as it does not protect the system.
fc040c7 👍 1 Selected: AE
if we are going off of network security. NIDS will monitor the whole network as opposed to just one host (HIPS). and a WAF protect the web application.
ProudFather 👍 3 Selected: E
A Web Application Firewall (WAF) is specifically designed to protect web applications from attacks such as SQL injection, cross-site scripting, and cross-site request forgery. It can filter and block malicious traffic, protecting the web application from vulnerabilities. A Security Information and Event Management (SIEM) system can be used to monitor network traffic and identify potential security threats. By analyzing logs from various sources, including the WAF, the SIEM can detect and respond to attacks in real-time.
c7b3ff0 👍 4 Selected: DE
Changing my previous answer. D&E. WAF protects the web application by filtering and monitoring HTTP/HTTPS traffic (port 443 is HTTPS). A HIPS installed on the web application's server will monitor/analyze activity with the ability to detect and prevent exploitation of vulnerabilities.
Ty13 👍 2 Selected: AE
A. NIDS E. WAF They're asking for setting things up. So set up a WAF and then a NIDS - anomalies would alert admins to take action. SIEM is good because it's still collecting data, but it's more about overall data security whereas NIDS is specifically for the network.
Szajba123 👍 2 Selected: E
Why: E. WAF (Web Application Firewall): A WAF is specifically designed to protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. It can help prevent attacks such as SQL injection, cross-site scripting (XSS), and other common web-based threats. Setting up a WAF on port 443 (which is used for HTTPS traffic) would directly address risks associated with web application vulnerabilities. F. SIEM (Security Information and Event Management): A SIEM system collects and analyzes security data from across the network, including logs and events from the web application. It provides real-time analysis, helps in detecting anomalies, and assists in responding to potential threats. This would complement the WAF by providing a broader view of security incidents and facilitating incident response.
ef5549f 👍 1
GPT: A & E
a4e15bd 👍 3 Selected: DE
Changing my previous answer. I got with D & E. Together these two tools should provide a comprehensive defense securing both the application and the underlying server.
suleman1000 👍 1 Selected: AE
NIDS and WAF
cri88 👍 2 Selected: AE
E. WAF (Web Application Firewall) A. NIDS (Network Intrusion Detection System) Explanation: E. WAF (Web Application Firewall): A WAF specifically protects web applications by filtering and monitoring HTTP/HTTPS traffic between a web application and the internet. It can help detect and block attacks targeting the web application, such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities. A. NIDS (Network Intrusion Detection System): NIDS monitors network traffic for suspicious activity and potential threats. Deploying NIDS can help detect malicious activity at the network level, including attempts to exploit vulnerabilities over port 443. These two options would significantly enhance the security of the web application by providing both application-level protection (WAF) and network-level monitoring (NIDS).
nyyankee718 👍 3 Selected: AE
Could be A and F also? NIDS (Network Intrusion Detection System): This system monitors network traffic for potential malicious activity, including attempts to exploit vulnerabilities in the web application. While it primarily detects rather than prevents, it provides valuable insights into potential threats and alerts the security team
mr_reyes 👍 3
Doesn't SIEM only monitor and report, not actually prevent? Wouldn't HIPS be more appropriate?
a4e15bd 👍 3
WAF and SIEM are correct answers.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Analysis

The scenario focuses on securing a web application communicating over port 443 (HTTPS) and explicitly requests "advanced network security capabilities." In the context of CompTIA Security+, this points toward solutions that operate at the network and application layers to filter, monitor, and protect external-facing services without relying on host-specific agents.

Why Option E (WAF) is Essential

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic destined for web applications. It mitigates layer 7 threats such as SQL injection, cross-site scripting (XSS), and OWASP Top 10 vulnerabilities. As multiple community members noted, a WAF directly addresses the application-layer attack surface mentioned in the prompt, making it an undeniable first choice.

Why Option A (NIDS) Completes the Solution

The second required control must align with the phrase "advanced network security capabilities." A Network Intrusion Detection System (NIDS) monitors inbound and outbound network traffic across the entire segment, identifying malicious patterns, exploits, or anomalous behavior targeting the web server. While a NIDS is primarily a detection tool, it provides the necessary visibility and alerting framework that complements the WAF’s filtering capabilities. Candidates who selected this pair correctly recognized that network-wide monitoring is distinct from host-based protection.

Why Other Options Fall Short

  • HIPS (Host-Based Intrusion Prevention System): While effective at preventing exploitation on the specific server, HIPS operates at the endpoint/OS level, not the network level. The prompt specifically asks for network security capabilities, which is why many candidates mistakenly chose DE instead of AE.
  • SIEM (Security Information and Event Management): Though highly valuable for centralized logging and correlation, a SIEM is a data aggregation and analytics platform, not a direct network security control that filters or blocks traffic.
  • Certificate Revocation List (CRL): This manages PKI trust but does not actively secure the web application’s attack surface against active exploits.
  • Honeypot: Used for deception and threat intelligence gathering, not for production defense of a live web application.

Official Reference

Exam Strategy

Always match the scope of the solution to the exact wording in the scenario; if the question specifies "network" security, prioritize network-layer controls like NIDS or NGFW over host-based tools like HIPS. When a question mentions a web application on port 443, immediately consider a WAF as a primary component of your answer.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide