How to Securely Provide Administrative Access While Minimizing Traffic?
A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the ability to distinguish between general network segmentation and dedicated hardened gateways, often trapping candidates who overgeneralize perimeter defenses or authentication protocols.
This question evaluates secure privileged access strategies, with overwhelming community consensus identifying a bastion host as the optimal solution for restricting administrative traffic across security boundaries.
Candidates frequently choose 'Deploying a perimeter network' or 'Installing a WAF', mistakenly assuming that broad isolation or web filtering inherently controls administrative traffic volume and privilege escalation pathways.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Bastion Hosts as Controlled Choke Points
A bastion host (frequently referred to as a jump server) is a rigorously hardened system engineered to serve as the exclusive gateway for privileged administrative access. By routing all management traffic through this single node, organizations can enforce strict allow/deny firewall policies, comprehensive audit logging, and robust authentication mechanisms. This architecture directly satisfies the requirement to minimize traffic allowed through the security boundary while maintaining a highly secure access path to internal assets.Why Alternative Options Fail the Criteria
While a perimeter network (Option B) establishes a defensive buffer zone, it describes a broad architectural layout rather than a specific mechanism for controlling administrative traffic flow. A Web Application Firewall (Option C) specializes in inspecting HTTP/HTTPS payloads to block web-based attacks, rendering it ineffective for managing non-web administrative protocols like SSH, RDP, or SNMP. Single sign-on (Option D) streamlines user authentication across multiple platforms but operates purely at the identity layer, offering zero visibility or restriction over actual network traffic crossing the security boundary. Although some test-takers initially question whether bastion hosts only apply to external users, modern security frameworks universally apply this hardened-gateway model to internal administrative workflows as well.Exam Context & Community Validation
Community feedback consistently reinforces that keywords like "minimizing traffic," "single point of entry," and "hardened access" are direct indicators for a bastion host. Several candidates noted the terminology overlap with jump servers, confirming that CompTIA accepts both concepts interchangeably in this context.Official Reference
- https://www.cisecurity.org/controls/cis-controls-list/v8/secure-infrastructure/standard-5-use-hardened-systems
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-41r1.pdf
- CompTIA Security+ SY0-701 Exam Objectives: Domain 2.0 - Architecture and Design
Exam Strategy
When a question emphasizes restricting traffic flow, enforcing a single entry point, or securing privileged sessions, immediately map those requirements to a bastion host or jump server. Reserve perimeter networks and SSO for scenarios focused on general network zoning or identity consolidation, respectively, to avoid being misled by broadly correct but functionally irrelevant distractors.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →