Which Control Best Blocks Externally Crafted Malicious Packets?
A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?
Community Votes
75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests inline network inspection versus host- or access-based controls, and the trap is choosing a network allow list because it sounds absolute but cannot analyze crafted packet payloads.
This SY0-701 scenario asks which control is the most secure way to harden a network against externally crafted malicious packets. The page explains why an intrusion prevention system (IPS) is the correct answer (C) by inspecting and blocking malicious traffic inline before it reaches internal hosts.
Many candidates choose E, the network allow list, because it conceptually blocks all traffic except trusted sources; however, it does not inspect packet content and can be bypassed through allowed protocols or compromised trusted hosts.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An intrusion prevention system (IPS) is the only option that actively inspects packet payloads and can drop malicious traffic inline before it reaches internal systems. It can detect patterns, signatures, and anomalies associated with externally crafted packets, which matches the scenario's network-hardening goal. By placing the IPS at the perimeter or a chokepoint, the organization gets both detection and prevention without relying on each endpoint. The exam's key distinction here is that IPS provides network-level, inline enforcement against malicious packets, not just logging or access control. Therefore C is the most secure method in the given list.Why the Other Options Are Wrong
A, anti-malware solutions, focus on endpoint malware execution and do not inspect network-crafted packets at the perimeter, so they leave the network path exposed. B, host-based firewalls, protect individual hosts but are not a centralized, network-wide inline inspection layer and depend on consistent host configuration. D, network access control (NAC), authenticates and authorizes devices before admission; it does not analyze packet content for crafted attacks. E, a network allow list, only permits trusted sources or services, but crafted malicious packets can originate from an allowed host, exploit an allowed protocol, or spoof a trusted address, so it is not the most secure control for this threat.Community Comment Notes
The commenter 1f2b013 argued that an IPS works by "analyzing and filtering packets before they reach the internal network," which aligns with the inline prevention rationale. Pitrix supported the network allow list as blocking untrusted external traffic, but that view treats source filtering as equivalent to payload inspection, which the exam does not. Anyio similarly noted that an IPS "blocks them before they can reach the internal network," reinforcing why C beats the other options. The community majority and the scorer's suggested key both land on C, and the technical reasoning supports that verdict.Official Reference
Exam Strategy
For SY0-701 network-hardening scenarios, identify the control that inspects traffic inline at the network boundary rather than on each endpoint. Eliminate anti-malware, host firewalls, NAC, and allow lists when the requirement is to block crafted packets, because none of them analyze packet content at the network chokepoint.
Frequently Asked Questions
Why is a network allow list not the most secure choice against crafted packets?
An allow list filters by trusted source or service but does not inspect packet content, so malicious payloads from permitted hosts or protocols can still reach internal systems.
Does a host-based firewall block externally crafted malicious packets as well as an IPS?
A host-based firewall protects only the host it runs on and does not provide inline, network-wide packet inspection at the perimeter, so it is less comprehensive than an IPS.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →