Courseiva
Question 234 of 464
Network SecurityhardMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

An organization wants to implement a security solution that uses a cloud-based service to inspect all incoming web traffic for malware and policy violations before it reaches the internal network. This type of solution is known as a:

⚠ Common exam trap

Many candidates confuse a Secure Web Gateway (SWG) with a Web Application Firewall (WAF), as both deal with web traffic, but SWG focuses on user-to-web traffic inspection and policy enforcement, while WAF protects a specific web server from application-layer attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Secure web gateway (SWG)

A Secure Web Gateway (SWG) is a cloud-based security solution that inspects all outbound and inbound web traffic for malware, policy violations, and data loss. It operates at the application layer, typically using proxy-based or API-based inspection to enforce security policies before traffic reaches the internal network. This matches the requirement for a cloud service that inspects incoming web traffic for malware and policy violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Web application firewall (WAF)

    Why it's wrong here

    A Web Application Firewall (WAF) specifically protects web applications from common application-layer attacks such as SQL injection, cross-site scripting (XSS), and broken authentication. It operates by filtering, monitoring, and blocking malicious HTTP traffic directed *at* web servers, rather than securing *outbound* web browsing for internal users. While cloud-based WAFs exist, their focus is on protecting an organization's *own* web applications, not providing a general cloud-based web security solution for client-side browsing.

    When this WOULD be correct

    A question asking for a solution that protects a specific web application from application-layer attacks (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS requests and responses, typically deployed in front of web servers.

  • Secure web gateway (SWG)

    Why this is correct

    A Secure Web Gateway (SWG) is precisely designed to filter and secure web traffic, often delivered as a cloud-based service. It acts as an intermediary proxy, inspecting all outbound and inbound web requests to block malware, enforce acceptable use policies, and prevent data loss. This cloud-native approach provides consistent security for users regardless of their location, making it ideal for distributed workforces and aligning perfectly with the need for a cloud-based security solution.

  • Intrusion detection system (IDS)

    Why it's wrong here

    An Intrusion Detection System (IDS) passively monitors network traffic for suspicious activities or known attack signatures, generating alerts when potential threats are identified. While it helps detect malicious patterns, an IDS does not actively block or filter web content in real-time as a proxy would, nor is its primary purpose to provide a cloud-based service for proactive web traffic security and policy enforcement. Its role is detection and alerting, not inline prevention of web-borne threats.

    When this WOULD be correct

    A question asking for a solution that monitors network traffic for signs of malicious activity and generates alerts without actively blocking traffic, such as 'An organization wants to detect potential intrusions on its internal network without affecting performance.'

  • VPN concentrator

    Why it's wrong here

    A VPN concentrator establishes and manages encrypted virtual private network tunnels, primarily for secure remote access to an organization's internal network. Its core function is authentication and encryption of network traffic between remote clients and the corporate network, not to actively inspect, filter, or secure general web browsing content for an entire organization via a cloud service. It facilitates secure *access*, rather than *filtering* web content.

    When this WOULD be correct

    An organization needs to provide secure remote access for employees connecting from external networks, requiring encrypted tunnels and authentication. The correct answer would be a VPN concentrator.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Secure web gateway (SWG)Correct answer

Why this is correct

A Secure Web Gateway (SWG) is precisely designed to filter and secure web traffic, often delivered as a cloud-based service. It acts as an intermediary proxy, inspecting all outbound and inbound web requests to block malware, enforce acceptable use policies, and prevent data loss. This cloud-native approach provides consistent security for users regardless of their location, making it ideal for distributed workforces and aligning perfectly with the need for a cloud-based security solution.

Web application firewall (WAF)Wrong answer — click to see why

Why this is wrong here

A WAF inspects and filters HTTP/HTTPS traffic to protect web applications from attacks like SQL injection, but it does not inspect all web traffic for malware and policy violations before reaching the internal network; that is the role of a secure web gateway (SWG).

★ When this WOULD be the correct answer

A question asking for a solution that protects a specific web application from application-layer attacks (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS requests and responses, typically deployed in front of web servers.

Why candidates choose this

Candidates may confuse WAF with SWG because both deal with web traffic filtering, but WAF focuses on application-layer attacks while SWG enforces broader security policies and malware inspection for all web traffic.

Intrusion detection system (IDS)Wrong answer — click to see why

Why this is wrong here

An IDS is a passive monitoring system that detects suspicious activity but does not inspect or block web traffic inline; it cannot enforce policies on incoming web traffic before it reaches the internal network.

★ When this WOULD be the correct answer

A question asking for a solution that monitors network traffic for signs of malicious activity and generates alerts without actively blocking traffic, such as 'An organization wants to detect potential intrusions on its internal network without affecting performance.'

Why candidates choose this

Candidates may confuse IDS with SWG because both involve security inspection, but IDS lacks the inline, cloud-based web traffic filtering and policy enforcement capabilities described in the question.

VPN concentratorWrong answer — click to see why

Why this is wrong here

A VPN concentrator is used to create secure tunnels for remote access or site-to-site connectivity, not to inspect web traffic for malware or policy violations. It does not perform content filtering or threat detection on incoming web traffic.

★ When this WOULD be the correct answer

An organization needs to provide secure remote access for employees connecting from external networks, requiring encrypted tunnels and authentication. The correct answer would be a VPN concentrator.

Why candidates choose this

Candidates may confuse VPN concentrators with security gateways because both are network security appliances, but VPN concentrators focus on encryption and access, not traffic inspection.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

OSI Model Reference

LayerNamePDUKey Protocols / Devices
7ApplicationDataHTTP, HTTPS, DNS, SMTP, FTP, SSH
6PresentationDataTLS / SSL, JPEG, ASCII encoding
5SessionDataNetBIOS, RPC, SIP
4TransportSegment / DatagramTCP, UDP
3NetworkPacketIP, ICMP, OSPF — Routers
2Data LinkFrameEthernet, Wi-Fi, PPP — Switches, Bridges
1PhysicalBitsCables, NICs, Hubs, Repeaters

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.