How to Securely Provide Administrative Access While Minimizing Traffic?

A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?

  1. Implementing a bastion host Source Reference Answer
  2. Deploying a perimeter network
  3. Installing a WAF
  4. Utilizing single sign-on

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the ability to distinguish between general network segmentation and dedicated hardened gateways, often trapping candidates who overgeneralize perimeter defenses or authentication protocols.

This question evaluates secure privileged access strategies, with overwhelming community consensus identifying a bastion host as the optimal solution for restricting administrative traffic across security boundaries.

Candidates frequently choose 'Deploying a perimeter network' or 'Installing a WAF', mistakenly assuming that broad isolation or web filtering inherently controls administrative traffic volume and privilege escalation pathways.

Community Discussion (9 comments)

metzen227 👍 20
Implementing a bastion host: A bastion host is a highly secured server located on a perimeter network (also known as a DMZ) that is designed to withstand attacks. It acts as a gateway between internal and external networks, allowing access only to specific services and applications. Users must authenticate themselves to the bastion host before accessing internal resources. This option provides a controlled entry point into the internal network, reducing the attack surface.
Markie100 👍 1 Selected: A
Implementing a bastion host is the most secure method for providing administrative access to internal resources while minimizing traffic through the security boundary. It ensures controlled, monitored, and hardened access, aligning with best practices for securing administrative workflows.
_thelastturtle 👍 1 Selected: B
I thought a bastion would be for external users.
kai001 👍 4 Selected: A
A bastion host is a highly secured server designed to be the single point of entry for administrative access to internal resources. It acts as a gateway, allowing administrators to connect securely to internal systems without directly exposing those systems to the outside world. Only specific, authorized traffic (e.g., SSH or RDP) is allowed, and the bastion host is heavily monitored and hardened against attacks, thus minimizing the traffic allowed through the security boundary.
c469c8e 👍 1 Selected: C
A bastion host is only to provide access from public to private network. Question is to provide administrative access to internal resources. This excludes bastion host. Only response is WAF
dbrowndiver 👍 1 Selected: A
The bastion host serves as a hardened gateway, where all administrative access to the internal network is funneled. This limits the exposure of the internal network to only a single, secure entry point. Security Features: Bastion hosts are typically configured with strong security measures, such as multi-factor authentication, logging, and monitoring, to ensure that only authorized users can access internal resources.
SHADTECH123 👍 1 Selected: A
Implementing a bastion host provides a highly secure method for administrative access to internal resources while minimizing traffic through the security boundary. It serves as a single entry point for remote administrative access, enforcing strong authentication and access controls before allowing access to internal systems.
shady23 👍 3 Selected: A
A. Implementing a bastion host The keyword in the question that makes option A correct is "minimizing the traffic allowed through the security boundary." Implementing a bastion host allows for strict control over inbound traffic from external networks by acting as a single point of entry. Users connect to the bastion host, and from there, access to internal resources is provided. This setup minimizes the direct traffic flow to internal resources, as all external access is channeled through the bastion host, which can enforce security measures such as authentication, authorization, and logging. This effectively reduces the amount of traffic allowed through the security boundary while still providing access to internal resources for administrative purposes.
e5c1bb5 👍 4 Selected: A
so from my understanding the bastion host and jump server are similar if not the name. the bastion host is not on the exam objectives. i think ill still go with A because it is the most secure. maybe its a no credit question?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Bastion Hosts as Controlled Choke Points

A bastion host (frequently referred to as a jump server) is a rigorously hardened system engineered to serve as the exclusive gateway for privileged administrative access. By routing all management traffic through this single node, organizations can enforce strict allow/deny firewall policies, comprehensive audit logging, and robust authentication mechanisms. This architecture directly satisfies the requirement to minimize traffic allowed through the security boundary while maintaining a highly secure access path to internal assets.

Why Alternative Options Fail the Criteria

While a perimeter network (Option B) establishes a defensive buffer zone, it describes a broad architectural layout rather than a specific mechanism for controlling administrative traffic flow. A Web Application Firewall (Option C) specializes in inspecting HTTP/HTTPS payloads to block web-based attacks, rendering it ineffective for managing non-web administrative protocols like SSH, RDP, or SNMP. Single sign-on (Option D) streamlines user authentication across multiple platforms but operates purely at the identity layer, offering zero visibility or restriction over actual network traffic crossing the security boundary. Although some test-takers initially question whether bastion hosts only apply to external users, modern security frameworks universally apply this hardened-gateway model to internal administrative workflows as well.

Exam Context & Community Validation

Community feedback consistently reinforces that keywords like "minimizing traffic," "single point of entry," and "hardened access" are direct indicators for a bastion host. Several candidates noted the terminology overlap with jump servers, confirming that CompTIA accepts both concepts interchangeably in this context.

Official Reference

Exam Strategy

When a question emphasizes restricting traffic flow, enforcing a single entry point, or securing privileged sessions, immediately map those requirements to a bastion host or jump server. Reserve perimeter networks and SSO for scenarios focused on general network zoning or identity consolidation, respectively, to avoid being misled by broadly correct but functionally irrelevant distractors.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide