CS0-003 · Question #78
A security administrator needs to provide access from partners to an Isolated laboratory network inside an organization that meets the following requirements: - The partners' PCs must not connect dire
The correct answer is A. Deployment of a jump box to allow access to the laboratory network and use of VDI in persistent. To provide secure, indirect, and persistent access for partners to an isolated lab network, deploying a jump box for controlled entry and using persistent VDI for analyses is the most suitable solution.
Question
A security administrator needs to provide access from partners to an Isolated laboratory network inside an organization that meets the following requirements:
- The partners' PCs must not connect directly to the laboratory
network.
- The tools the partners need to access while on the laboratory network
must be available to all partners
- The partners must be able to run analyses on the laboratory network,
which may take hours to complete Which of the following capabilities will MOST likely meet the security objectives of the request?
Options
- ADeployment of a jump box to allow access to the laboratory network and use of VDI in persistent
- BDeployment of a firewall to allow access to the laboratory network and use of VDI in non-
- CDeployment of a firewall to allow access to the laboratory network and use of VDI In persistent
- DDeployment of a jump box to allow access to the Laboratory network and use of VDI in non-
How the community answered
(57 responses)- A56% (32)
- B14% (8)
- C25% (14)
- D5% (3)
Why each option
To provide secure, indirect, and persistent access for partners to an isolated lab network, deploying a jump box for controlled entry and using persistent VDI for analyses is the most suitable solution.
Deploying a jump box (or bastion host) allows indirect, controlled access to the isolated laboratory network, fulfilling the 'partners' PCs must not connect directly' requirement. Using VDI (Virtual Desktop Infrastructure) in persistent mode ensures each partner has a consistent, personalized environment where their work, including analyses taking hours, can be saved and resumed across sessions, and common tools are readily available to all.
A firewall controls network traffic but does not provide the indirect access (jump box) or persistent user environment required. VDI in non-persistent mode would erase all changes and progress after each session, making it unsuitable for analyses that 'may take hours to complete'.
A firewall primarily controls network traffic and doesn't offer the secure indirect access a jump box provides. While VDI in persistent mode is correct for retaining work, the firewall alone doesn't meet the 'no direct connection' security objective in the same way a jump box does.
While a jump box provides indirect access, VDI in non-persistent mode would not retain analysis progress, making it unsuitable for tasks that 'may take hours to complete' as changes are wiped after each session, failing to meet a key requirement.
Concept tested: Secure remote access and virtual desktop solutions
Source: https://learn.microsoft.com/en-us/azure/virtual-desktop/overview
Topics
Community Discussion
No community discussion yet for this question.