How to Securely Access Segmented Internal Servers Under Compliance Requirements?
As part of new compliance audit requirements, multiple servers need to be segmented on different networks and should be reachable only from authorized internal systems. Which of the following would meet the requirements?
Community Votes
71% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between basic traffic filtering and creating a controlled, auditable access gateway for restricted internal networks.
This question evaluates the proper method for granting compliant, restricted access to network-segmented internal servers. Community consensus strongly supports deploying a jump server to enforce centralized authentication and auditing.
Candidates often select firewall rules because they associate network segmentation with packet filtering. However, firewalls alone lack the centralized authentication, session management, and granular audit trails that compliance frameworks require for sensitive internal resource access.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Jump Servers and Compliance
A jump server (also known as a bastion host) is a hardened system specifically designed to act as a single, controlled entry point into a restricted or segmented network. In compliance-driven environments, regulations often mandate that access to sensitive internal servers must be strictly monitored, authenticated, and logged. By routing all administrative or authorized access through an internal jump server, organizations can enforce multi-factor authentication, record detailed session logs, and limit direct exposure of backend servers.Why Option D is Correct
The prompt explicitly states that servers are "segmented on different networks" and must be "reachable only from authorized internal systems." A jump server fulfills both requirements by serving as the exclusive gateway for authorized traffic. It isolates the target servers from direct network paths while providing the auditable access channel required by compliance audits. Community discussions highlight that phrases like "isolated and authorized internal systems" are classic indicators for jump server deployments in certification exams.Why Other Options Are Incorrect
- Option A (Firewall rules): While firewalls are foundational for network segmentation and blocking external threats, they operate primarily as stateful filters. They do not inherently provide the centralized user authentication, interactive session management, or granular compliance auditing needed to satisfy strict regulatory requirements for internal server access.
- Option B (WAP): A Wireless Access Point extends network connectivity, typically to endpoints. Configuring one to allow access contradicts the requirement to restrict access to authorized internal systems and would unnecessarily expand the attack surface.
- Option C (IPSec tunnel): IPSec secures data in transit between two endpoints or networks through encryption. While useful for site-to-site connectivity, it does not address the access control, authentication, or auditing requirements specified in the scenario.
Exam Context
In SY0-701, questions emphasizing "compliance," "auditing," and "restricted internal access" consistently point toward solutions that centralize control and visibility. Recognizing the jump server as an access control mechanism rather than just a networking component is key to answering correctly.Official Reference
- https://www.comptia.org/training/books/sy0-701-comptia-security-study-guide-eighth-edition
- NIST Special Publication 800-53 Rev. 5 - Access Control (AC) Family
- CIS Critical Security Controls v8 - Control 4 & Control 16
Exam Strategy
When exam questions combine compliance or audit requirements with restricted network access, prioritize solutions that offer centralized authentication, logging, and monitoring over basic traffic-filtering tools. Look for keywords like 'segmented,' 'authorized only,' and 'auditable' to identify jump servers, bastion hosts, or Privileged Access Management (PAM) systems as the intended answer.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →