SY0-301 · Question #686
Sara, a security technician, has received notice that a vendor coming in for a presentation will require access to a server outside of the network. Currently, users are only able to access remote…
The correct answer is D. Write a firewall rule to allow the vendor to have access to the remote site. Writing a targeted firewall rule is the most controlled, least privilege approach: it grants the vendor access to only the specific remote server they need, without giving broader network access. Turning off the firewall (C) is a severe security risk and never acceptable…
Question
Sara, a security technician, has received notice that a vendor coming in for a presentation will require access to a server outside of the network. Currently, users are only able to access remote sites through a VPN connection. How could Sara BEST accommodate the vendor?
Options
- AAllow incoming IPSec traffic into the vendor's IP address.
- BSet up a VPN account for the vendor, allowing access to the remote site.
- CTurn off the firewall while the vendor is in the office, allowing access to the remote site.
- DWrite a firewall rule to allow the vendor to have access to the remote site.
How the community answered
(70 responses)- A13% (9)
- B6% (4)
- C3% (2)
- D79% (55)
Explanation
Writing a targeted firewall rule is the most controlled, least privilege approach: it grants the vendor access to only the specific remote server they need, without giving broader network access. Turning off the firewall (C) is a severe security risk and never acceptable. Setting up a full VPN account (B) grants wider access than necessary for a temporary guest. Allowing incoming IPSec traffic for the vendor's IP (A) is vague and would allow inbound connections, which is the wrong direction - the vendor inside the office needs outbound access to an external server.
Topics
Community Discussion
No community discussion yet for this question.