A security team is addressing a risk associated with the attack surface of the organization's web application over port 443. Currently, no advanced network security capabilities are in place. Which of the following would be best to set up? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: NIDS, WAF.
Why this is the answer
A Web Application Firewall (WAF) is best suited for protecting web applications by filtering and monitoring HTTP traffic between a web application and the internet. It can detect and block common web-based attacks such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 vulnerabilities, which are often exploited over port 443. A Network Intrusion Detection System (NIDS) monitors network traffic for suspicious activity and known attack signatures, providing an additional layer of defense by alerting administrators to potential breaches or policy violations that a WAF might miss or that occur at a different layer. Honeypots are decoys used to lure attackers and gather intelligence, not primary defense mechanisms. A Certificate Revocation List (CRL) is used for validating digital certificates, not for active threat prevention on a web application. A Host-based Intrusion Prevention System (HIPS) protects individual endpoints, not the network traffic to a web application. A Security Information and Event Management (SIEM) system aggregates and analyzes security logs, but it doesn't actively prevent attacks in real-time like a WAF or NIDS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed