CompTIA Server+ (SK0-005)Server AdministrationMedium
A server administrator needs to ensure that a new application server, hosting a payment gateway, can only communicate with a specific database server on port 3306 and a third-party API endpoint on port 443. All other outbound connections from the application server should be blocked. Which of the following networking components is BEST suited to enforce these granular communication restrictions at the server level?
- ALoad balancer
- BHost-based firewall
- CPerimeter firewall
- DNetwork Access Control (NAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Host-based firewall
A host-based firewall operates directly on the application server itself, allowing for granular control over inbound and outbound traffic specific to that server. This is the most effective way to enforce communication restrictions at the server level, independent of network-wide rules.
Why the other options are wrong
- A. A load balancer distributes incoming network traffic and does not enforce security policies for outbound connections from a server.
- C. A perimeter firewall protects the entire network and would not provide granular control for a single server's outbound connections.
- D. NAC controls network access based on device health and user authentication but does not typically enforce port-level communication restrictions for an already connected server.
Host-based Firewall
A software application that controls network traffic to and from a single computer, offering granular security policies.
- Operates at the operating system level.
- Provides granular control for individual servers.
- Protects against internal and external threats specific to the host.
Memory trick: Host's security is its own, not just the gate's.