Q: 8
82/315 Which of the following threat types involves an application that does not validate authorization for portions of itself beyond when the user first enters it?
Options
Discussion
Option D makes sense, it's about a bastion host that's hardened to only do what it's supposed to when exposed on the internet. Firewall and proxy are more about traffic control, not hosting the service itself. I think this is right, unless I'm missing something?
D , since a bastion host is designed to handle only specific public-facing functions and gets hardened for security. The question's focus on "desired operations" fits that better than a proxy or firewall. Pretty sure that's what they're looking for here.
D since a bastion host gets hardened to only allow those needed operations and is purposely exposed to the internet. Firewalls and proxies don't actually perform the ops themselves. Pretty sure that's what they're looking for but open to other takes.
Seen this phrased a few different ways, but always points to D in cloud and security contexts. Bastion hosts are pretty much hardened to do just what you need, nothing extra hanging around. Firewalls and proxies don’t really fit since they aren’t directly doing the operations, just filtering or relaying. Pretty sure D’s the way to go here unless something in the wording throws it off.
Had something like this in a mock, D for bastion host.
Its D, seen similar on practice exams. Official guide and labs both mention bastion hosts for this use case.
D for bastion host fits best, since it's a hardened system that's exposed directly to the internet and only handles specific tasks. Proxies forward requests but don't actually run the service. Pretty sure it's D, unless I'm missing a nuance here-let me know if you see it different.
That would be D, bastion. It's all about a hardened host set up for just specific public services. Proxy (B) sounds secure too but it doesn't actually run the operation, just forwards requests. Think I've seen this phrasing in practice sets before, so I'm pretty confident.
D vs B-proxy feels close but it's a distractor here, D is correct for hardened public systems.
C or D. Proxy is tempting but that's a distractor since it's not really running the service itself. Pretty sure it's D.
Be respectful. No spam.