Question 234 of 464
N10-009 Network Security Practice Question
An organization wants to implement a security solution that uses a cloud-based service to inspect all incoming web traffic for malware and policy violations before it reaches the internal network. This type of solution is known as a:
⚠ Common exam trap
Many candidates confuse a Secure Web Gateway (SWG) with a Web Application Firewall (WAF), as both deal with web traffic, but SWG focuses on user-to-web traffic inspection and policy enforcement, while WAF protects a specific web server from application-layer attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure web gateway (SWG)
A Secure Web Gateway (SWG) is a cloud-based security solution that inspects all outbound and inbound web traffic for malware, policy violations, and data loss. It operates at the application layer, typically using proxy-based or API-based inspection to enforce security policies before traffic reaches the internal network. This matches the requirement for a cloud service that inspects incoming web traffic for malware and policy violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Web application firewall (WAF)
Why it's wrong here
A Web Application Firewall (WAF) specifically protects web applications from common application-layer attacks such as SQL injection, cross-site scripting (XSS), and broken authentication. It operates by filtering, monitoring, and blocking malicious HTTP traffic directed *at* web servers, rather than securing *outbound* web browsing for internal users. While cloud-based WAFs exist, their focus is on protecting an organization's *own* web applications, not providing a general cloud-based web security solution for client-side browsing.
When this WOULD be correct
A question asking for a solution that protects a specific web application from application-layer attacks (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS requests and responses, typically deployed in front of web servers.
- ✓
Secure web gateway (SWG)
Why this is correct
A Secure Web Gateway (SWG) is precisely designed to filter and secure web traffic, often delivered as a cloud-based service. It acts as an intermediary proxy, inspecting all outbound and inbound web requests to block malware, enforce acceptable use policies, and prevent data loss. This cloud-native approach provides consistent security for users regardless of their location, making it ideal for distributed workforces and aligning perfectly with the need for a cloud-based security solution.
- ✗
Intrusion detection system (IDS)
Why it's wrong here
An Intrusion Detection System (IDS) passively monitors network traffic for suspicious activities or known attack signatures, generating alerts when potential threats are identified. While it helps detect malicious patterns, an IDS does not actively block or filter web content in real-time as a proxy would, nor is its primary purpose to provide a cloud-based service for proactive web traffic security and policy enforcement. Its role is detection and alerting, not inline prevention of web-borne threats.
When this WOULD be correct
A question asking for a solution that monitors network traffic for signs of malicious activity and generates alerts without actively blocking traffic, such as 'An organization wants to detect potential intrusions on its internal network without affecting performance.'
- ✗
VPN concentrator
Why it's wrong here
A VPN concentrator establishes and manages encrypted virtual private network tunnels, primarily for secure remote access to an organization's internal network. Its core function is authentication and encryption of network traffic between remote clients and the corporate network, not to actively inspect, filter, or secure general web browsing content for an entire organization via a cloud service. It facilitates secure *access*, rather than *filtering* web content.
When this WOULD be correct
An organization needs to provide secure remote access for employees connecting from external networks, requiring encrypted tunnels and authentication. The correct answer would be a VPN concentrator.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Secure web gateway (SWG)Correct answer▾
Why this is correct
A Secure Web Gateway (SWG) is precisely designed to filter and secure web traffic, often delivered as a cloud-based service. It acts as an intermediary proxy, inspecting all outbound and inbound web requests to block malware, enforce acceptable use policies, and prevent data loss. This cloud-native approach provides consistent security for users regardless of their location, making it ideal for distributed workforces and aligning perfectly with the need for a cloud-based security solution.
✗Web application firewall (WAF)Wrong answer — click to see why▾
Why this is wrong here
A WAF inspects and filters HTTP/HTTPS traffic to protect web applications from attacks like SQL injection, but it does not inspect all web traffic for malware and policy violations before reaching the internal network; that is the role of a secure web gateway (SWG).
★ When this WOULD be the correct answer
A question asking for a solution that protects a specific web application from application-layer attacks (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS requests and responses, typically deployed in front of web servers.
Why candidates choose this
Candidates may confuse WAF with SWG because both deal with web traffic filtering, but WAF focuses on application-layer attacks while SWG enforces broader security policies and malware inspection for all web traffic.
✗Intrusion detection system (IDS)Wrong answer — click to see why▾
Why this is wrong here
An IDS is a passive monitoring system that detects suspicious activity but does not inspect or block web traffic inline; it cannot enforce policies on incoming web traffic before it reaches the internal network.
★ When this WOULD be the correct answer
A question asking for a solution that monitors network traffic for signs of malicious activity and generates alerts without actively blocking traffic, such as 'An organization wants to detect potential intrusions on its internal network without affecting performance.'
Why candidates choose this
Candidates may confuse IDS with SWG because both involve security inspection, but IDS lacks the inline, cloud-based web traffic filtering and policy enforcement capabilities described in the question.
✗VPN concentratorWrong answer — click to see why▾
Why this is wrong here
A VPN concentrator is used to create secure tunnels for remote access or site-to-site connectivity, not to inspect web traffic for malware or policy violations. It does not perform content filtering or threat detection on incoming web traffic.
★ When this WOULD be the correct answer
An organization needs to provide secure remote access for employees connecting from external networks, requiring encrypted tunnels and authentication. The correct answer would be a VPN concentrator.
Why candidates choose this
Candidates may confuse VPN concentrators with security gateways because both are network security appliances, but VPN concentrators focus on encryption and access, not traffic inspection.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.