CAS-001 · Question #192
A company currently does not use any type of authentication or authorization service for remote access. The new security policy states that all remote access must be locked down to only authorized…
The correct answer is A. VPN concentrator B. Firewall. A VPN concentrator authenticates and authorizes remote users, ensuring only authorized personnel can establish remote access sessions - directly satisfying the 'authentication and authorization for remote access' requirement. A firewall enforces access control lists (ACLs) that…
Question
A company currently does not use any type of authentication or authorization service for remote access. The new security policy states that all remote access must be locked down to only authorized personnel. The policy also dictates that only authorized external networks will be allowed to access certain internal resources. Which of the following would MOST likely need to be implemented and configured on the company's perimeter network to comply with the new security policy? (Select TWO).
Options
- AVPN concentrator
- BFirewall
- CProxy server
- DWAP
- ELayer 2 switch
How the community answered
(36 responses)- A86% (31)
- C8% (3)
- D3% (1)
- E3% (1)
Explanation
A VPN concentrator authenticates and authorizes remote users, ensuring only authorized personnel can establish remote access sessions - directly satisfying the 'authentication and authorization for remote access' requirement. A firewall enforces access control lists (ACLs) that restrict which external networks can reach specific internal resources - satisfying the 'only authorized external networks' requirement. A proxy server manages outbound traffic filtering, not inbound remote access authentication. A WAP (Wireless Access Point) is for local wireless connectivity. A Layer 2 switch operates at the data link layer and provides no perimeter access control. Together, a VPN concentrator and firewall address both policy requirements on the perimeter.
Topics
Community Discussion
No community discussion yet for this question.