CompTIA Server+ (SK0-005)Server AdministrationHard

A server administrator is deploying a new application that uses a RESTful API and needs to be accessible by external clients over the internet. The application server is located in a private network segment. To allow inbound connections to the API while maintaining network security, which network device and configuration is primarily required?

  1. AA Layer 2 switch with VLANs.
  2. BA dedicated DNS server with public records.
  3. CA router with static routing.
  4. DA firewall configured with a NAT rule and ACL.
Show answer & explanation

Correct answer: D. A firewall configured with a NAT rule and ACL.

A firewall is essential for controlling inbound and outbound network traffic. To allow external clients to access an application server in a private network, a Network Address Translation (NAT) rule (specifically Destination NAT or Port Forwarding) is needed to translate the public IP:port to the private IP:port of the server. An Access Control List (ACL) is then used to explicitly permit only the required traffic (e.g., HTTPS on port 443) to the server, enhancing security.

Why the other options are wrong

  • A. A Layer 2 switch with VLANs segments local network traffic but does not provide routing or security for external internet access.
  • B. A dedicated DNS server translates domain names to IP addresses but does not handle network security, NAT, or traffic filtering for the server itself.
  • C. A router with static routing can forward traffic between networks but lacks the security features (packet filtering, NAT) needed to securely expose a private server to the internet.

Firewall NAT & ACL

A firewall uses Network Address Translation (NAT) to map public IP addresses/ports to private ones, and Access Control Lists (ACLs) to filter network traffic, allowing specific inbound/outbound connections while blocking others.

  • NAT enables private IPs to communicate with public internet.
  • ACLs define granular traffic permit/deny rules.
  • Essential for securely exposing internal services.

Memory trick: Firewall Filters, Forwards, Forbids

More Server Administration questions