Protecting Remote Data Without VPN

Answer Correct answer: A — The company should implement a Secure Web Gateway to filter web traffic and enforce security policies for remote employees without using a VPN.

A company recently decided to allow employees to work remotely. The company wants to protect its data without using a VPN. Which of the following technologies should the company implement?

  1. Secure web gateway Correct Answer
  2. Virtual private cloud endpoint
  3. Deep packet inspection
  4. Next-generation firewall

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of modern network security architectures that replace traditional VPNs with agent-based or cloud-based web gateways for remote workers.

This question addresses secure remote access alternatives to VPNs, identifying the Secure Web Gateway as the correct technology for filtering and protecting web traffic.

Candidates often choose Next-generation firewall (D) because it is a strong security tool, but NGFWs are typically perimeter devices rather than remote-access agents.

Community Discussion (4 comments)

7308365 👍 3
A. Secure Web Gateway (SWG) is an appliance or proxy server that mediates client connections with the internet by filtering spam and malware and enforcing access restrictions on types of sites visited, time spent, and bandwidth consumed. SWG also performs threat analysis and often integrates the functionality of data loss prevention (DLP) and cloud access security brokers (CASB) to protect against a full range of unauthorized egress threats, including malware command and control and data exfiltration.
ganymede 👍 2 Selected: A
A. Secure web gateway It's not VPC endpoint. It's not Deep packet inspection. Under the assumption comptia is talking about protecting data on the remote employee's machine, secure web gateway might be the best solution here. They would install an SWG agent into each remote worker's machine and the SWG solution would be cloud based.
Hs1208 👍 4 Selected: A
Secure web gateway (Option A): A secure web gateway is a security solution that filters web traffic to and from user devices, providing protection against web-based threats. It allows organizations to enforce security policies and protect users from malicious websites without the need for a VPN.
LuckyAro 👍 3 Selected: A
A secure web gateway would be a viable alternative.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Secure Web Gateway (SWG) is designed to filter internet-bound web traffic from users. For remote employees, an SWG agent can be installed on their device to route all web traffic through the company's security policies, providing protection against web-based threats without requiring a full-tunnel VPN.

Why the Other Options Are Wrong

Virtual private cloud endpoints (B) are used within cloud infrastructure (like AWS/Azure) to connect privately to services, not for general employee remote access. Deep packet inspection (C) is a feature or technique used by firewalls and gateways, not a standalone solution. Next-generation firewalls (D) are typically deployed at the network perimeter to protect internal networks from external attacks, rather than acting as individual agents for remote workers.

Community Comment Notes

Community consensus strongly supports Option A. As user Hs1208 noted, "A secure web gateway... allows organizations to enforce security policies and protect users from malicious websites without the need for a VPN." Another commenter, LuckyAro, simply affirmed that "A secure web gateway would be a viable alternative." Ganymede clarified that while an SWG agent might be installed locally, the solution itself is cloud-based and distinct from VPC endpoints or standard DPI.

Exam Strategy

When asked about remote access solutions that do not use a VPN, look for technologies that handle traffic filtering and policy enforcement at the endpoint or cloud level, such as Secure Web Gateways or Zero Trust Network Access (ZTNA).

Frequently Asked Questions

Why isn't a Next-Generation Firewall used for remote workers?

NGFWs are typically perimeter appliances. SWGs are better suited for remote users as they can be deployed as agents or proxies specifically for web traffic filtering.

How does an SWG differ from a VPN?

A VPN creates a tunnel for all traffic, while an SWG specifically filters and secures web traffic, often allowing non-web traffic to bypass the corporate network.

Related Analysis

← Back to SY0-601 Study Guide