nerdexam
Cisco

500-651 · Question #20

Which three NGFW and NGIPS features support the 'Complex Remote Access' use case? (Choose three.)

The correct answer is B. Users protected regardless of physical location E. Controls and protections extended beyond VPN controls F. Secure access extended to all users. Complex Remote Access describes a security scenario where users need protected connectivity from anywhere, and NGFW/NGIPS must extend enterprise-grade controls outside the traditional network perimeter. B, E, and F are correct because they directly describe this scenario: users…

Network Security

Question

Which three NGFW and NGIPS features support the 'Complex Remote Access' use case? (Choose three.)

Options

  • ASupport for device onboarding
  • BUsers protected regardless of physical location
  • CFuzzy Fingerprinting
  • DDetection of anomalous traffic
  • EControls and protections extended beyond VPN controls
  • FSecure access extended to all users

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    78% (21)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Complex Remote Access describes a security scenario where users need protected connectivity from anywhere, and NGFW/NGIPS must extend enterprise-grade controls outside the traditional network perimeter. B, E, and F are correct because they directly describe this scenario: users need protection wherever they are (B), the solution must deliver more than VPN tunneling alone - such as application control, IPS, and malware inspection (E), and the solution must cover every user, not just privileged subsets (F). Together, these three describe what makes remote access "complex" - it's not just a tunnel, it's full-stack security for all users everywhere.

Why the distractors are wrong:

  • A (Device onboarding) belongs to the Bring Your Own Device (BYOD) or Secure Connectivity use case, not Complex Remote Access.
  • C (Fuzzy Fingerprinting) is an OS/device fingerprinting technique used in network visibility/profiling contexts, unrelated to this use case.
  • D (Anomalous traffic detection) is an NGIPS capability tied to the Threat Detection use case, not Remote Access.

Memory tip: Think "BEF" - Beyond-perimeter protection, Extended controls (past VPN), For all users. If an answer is about who is protected, where they are, or what depth of control exists, it fits Complex Remote Access.

Topics

#Remote Access Security#Zero Trust Access#NGFW Features#User Protection

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice