Best Solution for Securing Internal Company Resources?
An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between user-facing traffic managers and admin-focused security isolators, with candidates often misattributing general web security features to privileged access control.
This question evaluates understanding of privileged access architectures designed to isolate and monitor administrative connections to critical systems. The community unanimously identifies a jump server as the correct implementation for adding a secure chokepoint before internal resources.
Candidates frequently choose Proxy server, reasoning that any intermediary device filters traffic and adds security. However, proxies primarily handle HTTP/HTTPS web requests, caching, and content filtering for end-users rather than enforcing strict access controls for administrative sessions into internal networks.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: The Jump Server Architecture
A jump server (also known as a bastion host or jump box) is specifically hardened and positioned as a controlled entry point for administrators accessing internal corporate resources. As highlighted by the community, it acts as a security chokepoint that enforces strong authentication, limits direct exposure of backend systems, and provides centralized logging and monitoring of all privileged sessions [[2], [7], [12]]. By forcing all administrative traffic through this isolated node, organizations significantly reduce their attack surface and prevent unauthorized lateral movement.Why Other Options Fall Short
- RDP server: Remote Desktop Protocol is simply a connectivity standard. Deploying an RDP server without additional isolation actually expands the attack surface by exposing sensitive management ports directly to networks, violating the principle of least privilege.
- Proxy server: While proxies do filter and cache web traffic, they are designed for end-user internet access or reverse-proxy web application protection, not for securing administrative access to internal infrastructure [[1], [4]]. Comment [5] notes reverse proxies can filter IPs, but in the context of SY0-701, a jump server is the definitive answer for internal resource isolation.
- Hypervisor: This is a virtualization platform that manages VMs. It has no inherent function in controlling or monitoring human/administrative access to internal company resources.
Exam Context & Consensus
With 97% community agreement, this question aligns perfectly with CompTIA Security+ objectives on network hardening and privileged access management. Recognizing keywords like "added layer of security," "preventing unauthorized access," and "internal company resources" should immediately trigger the jump server/bastion host concept in your mind.Official Reference
Exam Strategy
When questions mention securing administrative access to internal systems with an 'added layer' or 'chokepoint,' immediately prioritize jump servers, bastion hosts, or PAM solutions over general networking devices. Always differentiate between user-facing traffic controllers (proxies, load balancers) and admin-focused security isolators to avoid trap answers on the SY0-701 exam.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →