nerdexam
CompTIA

CAS-002 · Question #670

A company currently does not use any type of authentication or authorization service for remote access. The new security policy states that all remote access must be locked down to only authorized…

The correct answer is A. VPN concentrator B. Firewall. To enforce authenticated remote access and restrict external networks from reaching internal resources, a VPN concentrator and a firewall must be deployed at the perimeter.

Technical Integration of Enterprise Components

Question

A company currently does not use any type of authentication or authorization service for remote access. The new security policy states that all remote access must be locked down to only authorized personnel. The policy also dictates that only authorized external networks will be allowed to access certain internal resources. Which of the following would MOST likely need to be implemented and configured on the company's perimeter network to comply with the new security policy? (Select TWO).

Options

  • AVPN concentrator
  • BFirewall
  • CProxy server
  • DWAP
  • ELayer 2 switch

How the community answered

(49 responses)
  • A
    92% (45)
  • C
    4% (2)
  • D
    2% (1)
  • E
    2% (1)

Why each option

To enforce authenticated remote access and restrict external networks from reaching internal resources, a VPN concentrator and a firewall must be deployed at the perimeter.

AVPN concentratorCorrect

A VPN concentrator provides centralized authentication and authorization for remote users, ensuring only approved personnel can establish encrypted tunnels to the corporate network. It directly addresses the policy requirement that all remote access be restricted to authorized personnel.

BFirewallCorrect

A firewall inspects and filters traffic based on rules at the perimeter, enabling the organization to allow only authorized external networks to reach specific internal resources. This enforces the second policy requirement regarding network-level access control.

CProxy server

A proxy server intermediates client web requests for caching or content filtering but does not provide remote access authentication or perimeter network access control.

DWAP

A WAP (Wireless Access Point) provides local wireless LAN connectivity and is not a perimeter device for securing remote access or restricting external network traffic.

ELayer 2 switch

A Layer 2 switch operates at the data link layer to forward frames within a LAN segment and provides no authentication, authorization, or perimeter filtering capabilities.

Concept tested: VPN concentrator and firewall for perimeter security

Source: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-top

Topics

#VPN concentrator#firewall#remote access#network security policy

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice