Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 249 discussion

Actual exam question from ISC's CISSP
Question #: 249
Topic #: 1
[All CISSP Questions]

A hospital has allowed virtual private networking (VPN) access to remote database developers. Upon auditing the internal configuration, the network administrator discovered that split-tunneling was enabled. What is the concern with this configuration?

  • A. The network intrusion detection system (NIDS) will fail to inspect Secure Sockets Layer (SSL) traffic.
  • B. Remote sessions will not require multi-layer authentication.
  • C. Remote clients are permitted to exchange traffic with the public and private network.
  • D. Multiple Internet Protocol Security (IPSec) tunnels may be exploitable in specific circumstances.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CCNPWILL
5 months, 3 weeks ago
Selected Answer: C
As a CCNP, I can confirm that the answer is C. Without a shadow of a doubt.
upvoted 3 times
...
CL8282
7 months, 2 weeks ago
Selected Answer: C
C. Split tunneling allows only traffic destined for a specific network to flow through the VPN. All other traffic that is not specifically destined for the specific network will flow out to the internet.
upvoted 1 times
...
pete79
9 months, 2 weeks ago
Selected Answer: C
split tunnel allows connection to hospital network while at the same time allowing access to public network, that is why it is called split
upvoted 2 times
...
Soleandheel
11 months, 2 weeks ago
C. Remote clients are permitted to exchange traffic with the public and private network. Split-tunneling allows remote clients to route their internet traffic (public network) directly through their local internet connection while still maintaining a connection to the corporate network (private network) through the VPN. This means that traffic is divided between the public internet and the private corporate network.
upvoted 1 times
Soleandheel
11 months, 2 weeks ago
While split-tunneling can reduce the load on the corporate network and improve performance for the remote user, it also introduces security risks. By allowing remote clients to access the public internet while connected to the corporate network, it opens up the possibility for malware or attackers to potentially compromise the remote client and then use that compromised client to access the corporate network, thereby bypassing some of the security measures in place.
upvoted 1 times
...
...
74gjd_37
1 year, 2 months ago
In the Official ISC2 CISSP CBK (4th edition), page 607, it is mentioned that split-tunneling allows remote clients to access both the private network and the public internet simultaneously, potentially exposing the private network to security risks. This configuration can be exploited by attackers to gain unauthorized access to the private network through the public internet. Therefore, split-tunneling should be avoided, especially in sensitive environments such as hospitals.
upvoted 4 times
...
csco10320953
1 year, 8 months ago
Split tunnel is used for VPN client can access the internet directly instead of coming to Corp/office network. It doesn't meant will exchange the traffic bn Internet and Corp/office. Split tunneling failing to inspect the SSL traffic. So i will go with Answer A.
upvoted 1 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
DJOEK
1 year, 10 months ago
Selected Answer: C
Split-tunneling is a configuration that allows VPN clients to exchange traffic both with the public Internet and the private network at the same time. This can create a security concern because it allows remote clients to access resources on both the public Internet and the private network, potentially bypassing security controls that are in place on the private network. This can open the organization to a risk of data exfiltration and other malicious activity. A is true that a NIDS cannot inspect SSL traffic but what does this have to do with a split tunnel?
upvoted 2 times
jens23
1 year, 4 months ago
It means that the traffic is not tunneled to the corporate network where the security controls are made as it goes directly to the internet. The security concern with split-tunneling is, that the traffic that goes directly to the internet cannot be inspected.
upvoted 1 times
...
...
Delab202
1 year, 11 months ago
Selected Answer: D
What is the concern with this configuration? Not what is Split-tunneling? Multiple Internet Protocol Security (IPSec) tunnels may be exploitable in specific circumstances. IPsec (Internet Protocol Security) is a suite of protocols that secure network communication across IP networks. It provides security services for IP network traffic such as encrypting sensitive data, authentication, protection against replay and data confidentiality.
upvoted 1 times
...
iwannapass
1 year, 11 months ago
C. My reasoning: It defines what is Split-Tunneling. You can have the VPN to be connected to the business network while at the same time have access to the PUBLIC Internet. They nonchalantly throw it there that it is connected to a VPN and Public Internet like it's not a security concern. The end client can be exploited from the public side to enter the VPN and be a threat to the private network. sorry if my wording gave anyone a headache. wish I could draw it out
upvoted 2 times
...
Mann0302
2 years ago
Selected Answer: C
C clearly defines split-tunneling
upvoted 3 times
...
Jamati
2 years ago
Selected Answer: A
Correct answer is A
upvoted 3 times
...
sec_007
2 years ago
From this discussion, I would select A. https://www.auvik.com/franklyit/blog/vpn-split-tunneling/ But I am not so very sure. I think C is also correct, since it will also include scenario in A.
upvoted 1 times
...
franbarpro
2 years, 1 month ago
These are remote database developers. They should use VPN in a full tunneling mode.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...