nerdexam
CompTIA

SY0-501 · Question #311

A security administrator needs an external vendor to correct an urgent issue with an organization's physical access control system (PACS). The PACS does not currently have internet access because it…

The correct answer is C. Set up VPN concentrator for the vendor and restrict access to the PACS using desktop sharing. This question tests secure remote access methods for legacy systems requiring vendor support while maintaining security controls. The best solution provides controlled, auditable remote access without exposing the legacy system directly to the internet.

Submitted by jakub_pl· Mar 4, 2026Security architecture

Question

A security administrator needs an external vendor to correct an urgent issue with an organization's physical access control system (PACS). The PACS does not currently have internet access because it is running a legacy operation system. Which of the following methods should the security administrator select the best balances security and efficiency?

Options

  • ATemporarily permit outbound internet access for the pacs so desktop sharing can be set up
  • BHave the external vendor come onsite and provide access to the PACS directly
  • CSet up VPN concentrator for the vendor and restrict access to the PACS using desktop sharing
  • DSet up a web conference on the administrator's pc; then remotely connect to the pacs

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    82% (27)
  • D
    9% (3)

Why each option

This question tests secure remote access methods for legacy systems requiring vendor support while maintaining security controls. The best solution provides controlled, auditable remote access without exposing the legacy system directly to the internet.

ATemporarily permit outbound internet access for the pacs so desktop sharing can be set up

Temporarily granting outbound internet access to a legacy OS system directly exposes it to internet-based threats and vulnerabilities that the unpatched operating system cannot defend against, violating the principle of least exposure.

BHave the external vendor come onsite and provide access to the PACS directly

While having the vendor onsite eliminates remote access risks, it is not efficient for an urgent issue due to the time and logistics required for physical travel, failing the efficiency requirement of the scenario.

CSet up VPN concentrator for the vendor and restrict access to the PACS using desktop sharingCorrect

A VPN concentrator provides encrypted, authenticated remote access for the external vendor, while restricting access specifically to the PACS using desktop sharing ensures the vendor cannot access other network resources. This approach maintains the PACS's isolation from the public internet, enforces least-privilege access, and allows the administrator to monitor and terminate the session if needed - balancing both security and operational efficiency.

DSet up a web conference on the administrator's pc; then remotely connect to the pacs

Using the administrator's PC as a relay for a web conference and then remotely connecting to the PACS introduces an uncontrolled, unsecured intermediary path and does not provide proper authentication, access restriction, or auditability for the external vendor's session.

Concept tested: Secure third-party remote access to legacy systems

Source: https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways

Topics

#VPN#third-party vendor access#remote access#physical access control

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice