Courseiva
Security Architecture →mediumMultiple Choice

SY0-701 Security Architecture Practice Question

A financial services firm is designing a new online banking platform. The security team wants to ensure that even if an attacker compromises the web front-end, they cannot access the database directly. The design should enforce least privilege and provide a choke point for monitoring and logging. Which of the following security architecture concepts best meets this requirement?

⚠ Common exam trap

The trap here is assuming that host-based defenses or encryption at rest can prevent lateral movement from a compromised web server to the database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a screened subnet (DMZ) with a reverse proxy and a firewall between the web tier and the database tier.

The correct answer is the screened subnet with a reverse proxy and firewall between tiers. This design enforces network segmentation, least privilege, and provides a central point for monitoring and logging. Other options focus on host-level protection, data-at-rest encryption, or availability, none of which prevent lateral movement from a compromised web front-end to the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a screened subnet (DMZ) with a reverse proxy and a firewall between the web tier and the database tier.

    Why this is correct

    A screened subnet with a reverse proxy and firewall creates a segmented architecture where the web tier resides in a separate zone from the database tier. This enforces least privilege by limiting direct access to the database, and the firewall acts as a choke point for monitoring and logging. If the web front-end is compromised, the attacker cannot directly reach the database, satisfying the requirement.

  • ✗

    Deploy a host-based intrusion prevention system (HIPS) on the web servers.

    Why it's wrong here

    A HIPS on the web servers can detect and block some attacks on the web server itself, but it does not segment the network or prevent an attacker who has compromised the web server from pivoting to the database. It does not enforce least privilege between tiers or provide a network choke point for monitoring database access. Therefore, it fails to meet the core requirement.

  • ✗

    Use a load balancer to distribute traffic across multiple web servers.

    Why it's wrong here

    A load balancer improves availability and scalability by distributing incoming requests, but it does not isolate the web tier from the database tier or restrict access. An attacker on a compromised web server could still directly connect to the database if network paths allow. Thus, it does not satisfy the requirement for least privilege and a monitoring choke point.

  • ✗

    Enable full-disk encryption on the database servers.

    Why it's wrong here

    Full-disk encryption protects data at rest if the physical disk is stolen, but it does not prevent a compromised web front-end from accessing the database over the network. It does not enforce least privilege or create a segmentation boundary. Encryption at rest is valuable but irrelevant to the scenario of an attacker pivoting from a compromised web server to the database.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Go deeper

Related to this question

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.