Which Controls Secure Remote Access to Sensitive PHI Applications?
An organization wants to implement a secure solution for remote users. The users handle sensitive PHI on a regular basis and need to access an internally developed corporate application. Which of the following best meet the organization's security requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests defense-in-depth for remote sensitive access, where candidates often fall into the trap of selecting perimeter or web-layer tools instead of recognizing that strong identity verification (MFA) paired with a controlled gateway (Jump Server) is required.
Securing remote access to internal applications handling sensitive PHI requires strong authentication and a controlled entry point. The community consensus identifies Multi-Factor Authentication (MFA) and a Jump Server as the optimal combination to meet these compliance and security requirements.
Candidates frequently select WAF or Perimeter Network, mistaking web/application-layer protections for comprehensive remote access security. These controls do not authenticate individual remote users or restrict direct backend access, making them insufficient for PHI compliance.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept & Correct Answers
The scenario demands a secure architecture for remote users accessing an internal application containing sensitive PHI. To satisfy both security and compliance standards (like HIPAA), organizations must implement defense-in-depth focusing on identity verification and access containment. Multi-Factor Authentication (MFA) is mandatory to prevent unauthorized credential-based access to highly regulated data. Concurrently, a Jump Server (or bastion host) acts as a hardened, auditable intermediary that isolates remote users from the internal network, ensuring all sessions are logged, monitored, and restricted to necessary privileges.Why Other Options Fall Short
- Local administrative password: This manages workstation-level privilege escalation and has no bearing on securing remote application access or protecting PHI in transit.
- Perimeter network: While foundational to network segmentation, it is a broad architectural concept rather than a specific control for authenticating and monitoring remote user sessions.
- WAF (Web Application Firewall): A WAF filters malicious HTTP/HTTPS traffic targeting web applications but does not verify remote user identities or encrypt/manage interactive remote sessions. As noted in community discussions, WAFs protect the application layer but fail to address the authentication and session-control gaps highlighted in the prompt.
Exam Context & Compliance Note
Although the provided suggested answer lists only E, SY0-701 questions requiring two selections logically pair MFA with a secure access gateway. Community feedback consistently validates C and E as the correct pairing, emphasizing that jump servers provide the encrypted tunnel/control plane and auditing capabilities, while MFA satisfies the strict identity requirements for PHI. When you see 'sensitive data' + 'remote access', always prioritize IAM controls paired with secure connectivity mechanisms.Official Reference
- https://aao-hpf.org/wp-content/uploads/2021/06/SY0-701-Objectives.pdf
- https://www.nist.gov/cyberframework/summary-table
- https://www.hhs.gov/hipaa/for-professionals/security/index.html
- RFC 4301 - Security Architecture for the Internet Protocol
Exam Strategy
Always map the question keywords directly to CompTIA domains before scanning options. When prompted about remote access to sensitive/internal systems, immediately filter for identity/authentication controls (MFA, PKI) and secure access gateways (Jump Server, Bastion Host, Zero Trust Network Access). Avoid selecting perimeter or web-layer tools if the core issue revolves around user authentication and session auditing.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →