CompTIA Server+ (SK0-005)Server AdministrationHard

A server administrator is deploying a new application that uses a RESTful API. The application server needs to communicate securely with a backend database server located in a different network segment. Which network configuration ensures both secure and efficient communication between these two servers?

  1. AImplementing a firewall rule to allow only the specific application port (e.g., 443) and database port (e.g., 3306) between their respective servers.
  2. BOpening all ports between the two network segments.
  3. CConfiguring a VPN tunnel between the application and database servers.
  4. DPlacing both servers on the same flat network segment.
Show answer & explanation

Correct answer: A. Implementing a firewall rule to allow only the specific application port (e.g., 443) and database port (e.g., 3306) between their respective servers.

Implementing firewall rules to allow only necessary ports (like 443 for HTTPS/API and 3306 for MySQL/MariaDB) between specific servers adheres to the principle of least privilege in networking, ensuring security while maintaining efficient communication.

Why the other options are wrong

  • B. Opening all ports between network segments is a significant security risk and violates the principle of least privilege, making the network vulnerable.
  • C. A VPN tunnel provides strong encryption but can introduce overhead and might be overkill if only specific port-level security is needed and segments are within the same trusted network boundary.
  • D. Placing both servers on the same flat network segment removes network segmentation, increasing the attack surface and making it harder to control traffic flow, thus reducing security.

Network Segmentation and Firewall Rules

Network segmentation divides a network into smaller, isolated segments, and firewall rules control traffic flow between these segments based on protocols, ports, and IP addresses.

  • Enhances security by limiting the spread of breaches.
  • Applies the principle of least privilege to network access.
  • Requires careful planning to avoid disrupting legitimate traffic.

Memory trick: Firewall Rules Control Connections Safely.

More Server Administration questions