CompTIA Server+ (SK0-005)Server AdministrationMedium
A server administrator needs to ensure that a newly deployed application server can only communicate with the database server on port 3306 and the web server on port 80 and 443. All other outbound and inbound traffic should be blocked by default. Which of the following network configuration practices should the administrator implement?
- AAssign the application server a static IP address within a restricted subnet.
- BUtilize VLAN tagging to isolate the application server on a separate network segment.
- CImplement a host-based firewall with explicit allow rules and a default deny policy.
- DConfigure DNS records to resolve only to the allowed server IPs.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement a host-based firewall with explicit allow rules and a default deny policy.
To achieve granular control over specific ports and protocols, a host-based firewall is the most effective solution. It allows for explicit rules to permit only necessary traffic while blocking everything else by default.
Why the other options are wrong
- A. Assigning a static IP and using a restricted subnet helps with network organization but doesn't inherently block specific ports or enforce a default deny policy without a firewall.
- B. VLAN tagging isolates network segments, but doesn't control specific port communication between servers within or across segments without additional firewall rules.
- D. DNS records manage name resolution, not network traffic filtering.
Host-based Firewall
A software application that controls network traffic to and from a single server or workstation.
- Operates at the host level, not the network perimeter.
- Provides granular control over ports, protocols, and applications.
- Essential for 'defense in depth' strategies.
Memory trick: Firewall shields the server, allowing only essential traffic through its gates.