What Advanced Network Security Controls Protect a Web App on Port 443?
A security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place. Which of the following would be best to set up? (Choose two.)
Community Votes
63% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the ability to differentiate between host-based and network-based security controls, with the common trap being selecting HIPS instead of NIDS due to confusion over prevention versus detection capabilities.
This question tests selecting appropriate security controls to mitigate risks on a web application's HTTPS traffic. The majority of candidates agree that a WAF and NIDS provide the best combination of application-level filtering and network-wide monitoring.
Many candidates incorrectly choose HIPS and WAF (DE), believing that host-based prevention paired with a WAF offers complete coverage. However, HIPS operates at the endpoint level rather than providing the "advanced network security capabilities" explicitly requested by the scenario.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Analysis
The scenario focuses on securing a web application communicating over port 443 (HTTPS) and explicitly requests "advanced network security capabilities." In the context of CompTIA Security+, this points toward solutions that operate at the network and application layers to filter, monitor, and protect external-facing services without relying on host-specific agents.Why Option E (WAF) is Essential
A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic destined for web applications. It mitigates layer 7 threats such as SQL injection, cross-site scripting (XSS), and OWASP Top 10 vulnerabilities. As multiple community members noted, a WAF directly addresses the application-layer attack surface mentioned in the prompt, making it an undeniable first choice.Why Option A (NIDS) Completes the Solution
The second required control must align with the phrase "advanced network security capabilities." A Network Intrusion Detection System (NIDS) monitors inbound and outbound network traffic across the entire segment, identifying malicious patterns, exploits, or anomalous behavior targeting the web server. While a NIDS is primarily a detection tool, it provides the necessary visibility and alerting framework that complements the WAF’s filtering capabilities. Candidates who selected this pair correctly recognized that network-wide monitoring is distinct from host-based protection.Why Other Options Fall Short
- HIPS (Host-Based Intrusion Prevention System): While effective at preventing exploitation on the specific server, HIPS operates at the endpoint/OS level, not the network level. The prompt specifically asks for network security capabilities, which is why many candidates mistakenly chose DE instead of AE.
- SIEM (Security Information and Event Management): Though highly valuable for centralized logging and correlation, a SIEM is a data aggregation and analytics platform, not a direct network security control that filters or blocks traffic.
- Certificate Revocation List (CRL): This manages PKI trust but does not actively secure the web application’s attack surface against active exploits.
- Honeypot: Used for deception and threat intelligence gathering, not for production defense of a live web application.
Official Reference
- https://www.cisco.com/site/us/en/learn/topics/security/web-application-firewall.html
- https://www.sans.org/white-papers/intrusion-detection-systems/
- CompTIA Security+ SY0-701 Exam Objectives: Network Security
Exam Strategy
Always match the scope of the solution to the exact wording in the scenario; if the question specifies "network" security, prioritize network-layer controls like NIDS or NGFW over host-based tools like HIPS. When a question mentions a web application on port 443, immediately consider a WAF as a primary component of your answer.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →