CompTIA Security+ SY0-701 (V7) Practice Question

A security administrator needs to configure a firewall to protect internal database servers. According to company policy, only employees connected to the corporate VPN, which uses the 10.200.0.0/16 IP range, should be able to access the servers. All other inbound traffic must be blocked. Which configuration BEST enforces this policy while adhering to the principle of least privilege?

  • Create a single inbound rule to deny all traffic destined for the database servers.

  • Create an outbound rule to allow traffic from the servers to the 10.200.0.0/16 destination.

  • Create an inbound rule to allow traffic from the 10.200.0.0/16 source and rely on an implicit deny for all other traffic.

  • Create a default 'allow all' inbound rule and add a second rule to deny traffic from the 10.200.0.0/16 source.

CompTIA Security+ SY0-701 (V7)
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Security+ Voucher with Retake
v7 / SY0-701
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot