CAS-002 · Question #179
Which of the following provides the HIGHEST level of security for an integrated network providing services to authenticated corporate users?
The correct answer is C. Port security on switches, point to point VPN tunnels for user server connections, two-factor. Port security, point-to-point VPN tunnels for user-to-server connections, and two-factor authentication together provide layered access control appropriate for an integrated corporate network serving authenticated users.
Question
Which of the following provides the HIGHEST level of security for an integrated network providing services to authenticated corporate users?
Options
- APoint to point VPN tunnels for external users, three-factor authentication, a cold site, physical
- BIPv6 networking, port security, full disk encryption, three-factor authentication, cloud based
- CPort security on switches, point to point VPN tunnels for user server connections, two-factor
- DPort security on all switches, point to point VPN tunnels for user connections to servers, two-
How the community answered
(26 responses)- A12% (3)
- B19% (5)
- C65% (17)
- D4% (1)
Why each option
Port security, point-to-point VPN tunnels for user-to-server connections, and two-factor authentication together provide layered access control appropriate for an integrated corporate network serving authenticated users.
Including a cold site is a disaster recovery control rather than a day-to-day security control, making this combination less focused on the integrated network security scenario described.
IPv6 is a protocol version change and not inherently a security improvement, and cloud-based services introduce external dependencies that may not align with an integrated corporate network model.
Port security on switches prevents unauthorized devices from connecting to the corporate network by restricting which MAC addresses are permitted on each switch port. Point-to-point VPN tunnels encrypt traffic between users and servers, protecting data in transit on the internal network from eavesdropping or tampering. Two-factor authentication ensures that only properly authenticated corporate users can access resources, providing strong identity assurance suited to the integrated corporate environment described.
This option closely resembles C but the truncated text prevents full evaluation; C provides the most precisely and completely described combination of controls for the stated scenario.
Concept tested: Layered network access controls for authenticated corporate users
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-77r1.pdf
Topics
Community Discussion
No community discussion yet for this question.