Which Architecture Reduces VPN Traffic and Monitors Remote Employee Internet Use?

An organization is struggling with scaling issues on its VPN concentrator and internet circuit due to remote work. The organization is looking for a software solution that will allow it to reduce traffic on the VPN and internet circuit, while still providing encrypted tunnel access to the data center and monitoring of remote employee internet traffic. Which of the following will help achieve these objectives?

  1. Deploying a SASE solution to remote employees Source Reference Answer
  2. Building a load-balanced VPN solution with redundant internet
  3. Purchasing a low-cost SD-WAN solution for VPN traffic
  4. Using a cloud provider to create additional VPN concentrators

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to distinguish between legacy infrastructure scaling and cloud-native architectural convergence, with the primary trap being the intuitive but incorrect choice of adding more hardware to solve a scalability and visibility problem.

This question evaluates understanding of modern secure network frameworks designed for distributed workforces. The community unanimously identifies SASE as the optimal solution because it converges networking and security in the cloud, eliminating traditional VPN bottlenecks while enabling centralized traffic inspection.

Candidates frequently select option B or D, assuming that distributing load across multiple VPN concentrators or redundant circuits will resolve scaling limits. However, these approaches ignore the requirement for centralized internet traffic monitoring and perpetuate inefficient backhauling, which continues to strain the corporate internet circuit.

Community Discussion (5 comments)

geocis 👍 13
Answer is A......SASE (Secure Access Service Edge) is a comprehensive networking and security approach that combines wide-area networking (WAN) capabilities with security features. It provides secure access to applications and data, including encrypted tunnel access to the data center, while also offering monitoring capabilities for remote employee internet traffic. By implementing a SASE solution, the organization can reduce traffic on the VPN and internet circuit by routing traffic intelligently through the cloud, closer to the users. This approach helps optimize performance and security, addressing the scaling issues effectively.
dbrowndiver 👍 7 Selected: A
Deploying a SASE solution to remote employees is the best choice because it provides a holistic approach to secure remote access by reducing traffic, offering encrypted tunnel access, and monitoring internet traffic. SASE integrates necessary networking and security functions into a cloud-based solution, making it ideal for modern remote work environments.
9149f41 👍 2 Selected: A
SASE includes: SD-WAN has capability of taffic load balancing. SD-WAN, a core part of SASE, can dynamically route traffic across multiple connections. SASE also included: Firewalls, Secure web gateways
a4e15bd 👍 1
The correct answer is A. Deploying SASE Solution.. Secure Access Service Edge (SASE) is a network architecture framework that combines cloud-based security technologies with wide area network capabilities. The goal of SASE is to securely connect users, systems, and endpoints to applications and services anywhere
123456789User 👍 3 Selected: A
Deploying a SASE solution to remote employees.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the SASE Framework

Secure Access Service Edge (SASE) is a cloud-delivered architecture that merges wide area networking (WAN) capabilities with comprehensive security functions. As highlighted by community experts, SASE integrates SD-WAN, Secure Web Gateways (SWG), Firewall-as-a-Service (FWaaS), and Zero Trust Network Access (ZTNA) into a unified platform. This convergence directly addresses the organization's pain points by routing remote user traffic locally to the internet for web content while securely tunneling only necessary data center traffic through encrypted channels.

Why Option A is Correct

Deploying a SASE solution eliminates the need for a centralized, bottleneck-prone VPN concentrator. By leveraging local internet breakout, SASE significantly reduces bandwidth consumption on the corporate internet circuit and removes the scaling limitations of traditional hardware appliances. Furthermore, because security policies are enforced at the edge in the cloud, the organization gains real-time monitoring and inspection of all remote employee internet traffic without compromising performance or requiring complex on-premises management.

Why the Other Options Are Incorrect

Option B (load-balanced VPN) and Option D (additional VPN concentrators) attempt to scale a legacy architecture. While they may handle more concurrent connections, they do not solve the fundamental inefficiency of backhauling all internet traffic to the data center, nor do they inherently provide advanced internet traffic monitoring. Option C (SD-WAN) focuses primarily on intelligent traffic routing and path selection but lacks the integrated security stack (like SWG and threat prevention) required to monitor and secure remote internet usage effectively. As noted in the discussion, SD-WAN is actually a component within a SASE framework, making standalone SD-WAN insufficient for this scenario.

Official Reference

Exam Strategy

When encountering scenarios involving remote work scalability and security consolidation, prioritize cloud-native, converged frameworks over traditional hardware scaling. Always cross-reference the question's explicit requirements—such as both encrypted access and traffic monitoring—with the core capabilities of each technology to avoid falling for plausible but incomplete alternatives like standalone SD-WAN or redundant VPNs.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide