nerdexam
CompTIA

CNX-001 · Question #62

A network architect must ensure only certain departments can access specific resources while on premises. Those same users cannot be allowed to access those resources once they have left campus…

The correct answer is B. Configuring geofencing with the IPs of the resources. Geofencing uses defined geographic or network boundaries - in this case, the IP address ranges associated with on-premises resources - to enforce access policies. By configuring geofencing tied to the on-premises IP space, users inside those IP boundaries (on campus) can access…

Cloud Network Security

Question

A network architect must ensure only certain departments can access specific resources while on premises. Those same users cannot be allowed to access those resources once they have left campus. Which of the following would ensure access is provided according to these requirements?

Options

  • AEnabling MFA for only those users within the departments needing access
  • BConfiguring geofencing with the IPs of the resources
  • CConfiguring UEBA to monitor all access to those resources during non-business hours
  • DImplementing a PKI-based authentication system to ensure access

How the community answered

(45 responses)
  • A
    11% (5)
  • B
    80% (36)
  • C
    2% (1)
  • D
    7% (3)

Explanation

Geofencing uses defined geographic or network boundaries - in this case, the IP address ranges associated with on-premises resources - to enforce access policies. By configuring geofencing tied to the on-premises IP space, users inside those IP boundaries (on campus) can access the resources, while the same users lose access the moment they leave campus and no longer originate traffic from those IPs. MFA (A) adds authentication strength but does not restrict access based on physical location. UEBA (C) monitors behavior but does not actively block access. PKI (D) verifies identity but also does not enforce location-based restrictions.

Topics

#Geofencing#Location-based access control#Network access control#On-premises security

Community Discussion

No community discussion yet for this question.

Full CNX-001 Practice