CAS-001 · Question #355
Which of the following provides the HIGHEST level of security for an integrated network providing services to authenticated corporate users?
The correct answer is C. Port security on switches, point to point VPN tunnels for user server connections, two-factor cryptographic. Option C combines port security on switches (preventing unauthorized devices from connecting to the LAN), point-to-point VPN tunnels for user-to-server connections (encrypting internal traffic), and two-factor cryptographic authentication (strong identity verification using…
Question
Which of the following provides the HIGHEST level of security for an integrated network providing services to authenticated corporate users?
Options
- APoint to point VPN tunnels for external users, three-factor authentication, a cold site, physical security
- BIPv6 networking, port security, full disk encryption, three-factor authentication, cloud based servers, and
- CPort security on switches, point to point VPN tunnels for user server connections, two-factor cryptographic
- DPort security on all switches, point to point VPN tunnels for user connections to servers, two- factor
How the community answered
(47 responses)- A11% (5)
- B19% (9)
- C66% (31)
- D4% (2)
Explanation
Option C combines port security on switches (preventing unauthorized devices from connecting to the LAN), point-to-point VPN tunnels for user-to-server connections (encrypting internal traffic), and two-factor cryptographic authentication (strong identity verification using something you have-a cryptographic token-plus something you know). This layered approach addresses physical access, network-layer encryption, and authentication security simultaneously. The answer choices in this question are truncated, but Option C's combination of controls addresses the broadest range of threats for an integrated corporate network. The use of cryptographic (hardware) tokens for two-factor authentication is stronger than software-based MFA alone.
Topics
Community Discussion
No community discussion yet for this question.