Which Control Best Blocks Externally Crafted Malicious Packets?

Answer Correct answer: C — An intrusion prevention system (IPS) inspects traffic inline and blocks externally crafted malicious packets before they reach the internal network.

A security team is in the process of hardening the network against externally crafted malicious packets. Which of the following is the most secure method to protect the internal network?

  1. Anti-malware solutions
  2. Host-based firewalls
  3. Intrusion prevention systems Correct Answer
  4. Network access control
  5. Network allow list

Community Votes

C
75%
E
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests inline network inspection versus host- or access-based controls, and the trap is choosing a network allow list because it sounds absolute but cannot analyze crafted packet payloads.

This SY0-701 scenario asks which control is the most secure way to harden a network against externally crafted malicious packets. The page explains why an intrusion prevention system (IPS) is the correct answer (C) by inspecting and blocking malicious traffic inline before it reaches internal hosts.

Many candidates choose E, the network allow list, because it conceptually blocks all traffic except trusted sources; however, it does not inspect packet content and can be bypassed through allowed protocols or compromised trusted hosts.

Community Discussion (3 comments)

Pitrix 👍 1 Selected: E
E. Network allow list Here’s why: • A network allow list (also known as a whitelist) ensures that only trusted sources or specific IP addresses are allowed to send traffic to the internal network. This approach effectively blocks all untrusted external traffic, which directly prevents malicious packets from entering the network in the first place.
Anyio 👍 1 Selected: C
C. Intrusion Prevention Systems (IPS) Explanation: An Intrusion Prevention System (IPS) actively monitors network traffic for suspicious patterns or malicious packets and blocks them before they can reach the internal network. IPS is specifically designed to detect and prevent externally crafted malicious packets, making it the most secure and effective solution for this scenario. Other Options: B. Host-based firewalls: While useful for protecting individual devices, they are not sufficient to secure the entire internal network from malicious packets. D. Network access control (NAC): NAC is focused on ensuring that only authorized devices can connect to the network but does not inspect or block malicious packets. E. Network allow list: This approach can restrict access to only known safe sources but is less dynamic and effective against crafted malicious packets compared to IPS.
1f2b013 👍 2 Selected: C
An IPS provides comprehensive protection against malicious network traffic by analyzing and filtering packets before they reach the internal network.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An intrusion prevention system (IPS) is the only option that actively inspects packet payloads and can drop malicious traffic inline before it reaches internal systems. It can detect patterns, signatures, and anomalies associated with externally crafted packets, which matches the scenario's network-hardening goal. By placing the IPS at the perimeter or a chokepoint, the organization gets both detection and prevention without relying on each endpoint. The exam's key distinction here is that IPS provides network-level, inline enforcement against malicious packets, not just logging or access control. Therefore C is the most secure method in the given list.

Why the Other Options Are Wrong

A, anti-malware solutions, focus on endpoint malware execution and do not inspect network-crafted packets at the perimeter, so they leave the network path exposed. B, host-based firewalls, protect individual hosts but are not a centralized, network-wide inline inspection layer and depend on consistent host configuration. D, network access control (NAC), authenticates and authorizes devices before admission; it does not analyze packet content for crafted attacks. E, a network allow list, only permits trusted sources or services, but crafted malicious packets can originate from an allowed host, exploit an allowed protocol, or spoof a trusted address, so it is not the most secure control for this threat.

Community Comment Notes

The commenter 1f2b013 argued that an IPS works by "analyzing and filtering packets before they reach the internal network," which aligns with the inline prevention rationale. Pitrix supported the network allow list as blocking untrusted external traffic, but that view treats source filtering as equivalent to payload inspection, which the exam does not. Anyio similarly noted that an IPS "blocks them before they can reach the internal network," reinforcing why C beats the other options. The community majority and the scorer's suggested key both land on C, and the technical reasoning supports that verdict.

Official Reference

Exam Strategy

For SY0-701 network-hardening scenarios, identify the control that inspects traffic inline at the network boundary rather than on each endpoint. Eliminate anti-malware, host firewalls, NAC, and allow lists when the requirement is to block crafted packets, because none of them analyze packet content at the network chokepoint.

Frequently Asked Questions

Why is a network allow list not the most secure choice against crafted packets?

An allow list filters by trusted source or service but does not inspect packet content, so malicious payloads from permitted hosts or protocols can still reach internal systems.

Does a host-based firewall block externally crafted malicious packets as well as an IPS?

A host-based firewall protects only the host it runs on and does not provide inline, network-wide packet inspection at the perimeter, so it is less comprehensive than an IPS.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide