Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 277 discussion

Actual exam question from ISC's CISSP
Question #: 277
Topic #: 1
[All CISSP Questions]

An information technology (IT) employee who travels frequently to various countries remotely connects to an organization's resources to troubleshoot problems.
Which of the following solutions BEST serves as a secure control mechanism to meet the organization's requirements?

  • A. Install a third-party screen sharing solution that provides remote connection from a public website.
  • B. Install a bastion host in the demilitarized zone (DMZ) and allow multi-factor authentication (MFA) access.
  • C. Implement a Dynamic Domain Name Services (DONS) account to initiate a virtual private network (VPN) using the DONS record.
  • D. Update the firewall rules to include the static Internet Protocol (IP) addresses of the locations where the employee connects from.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Soleandheel
11 months, 2 weeks ago
B. Install a bastion host in the demilitarized zone (DMZ) and allow multi-factor authentication (MFA) access. Here's why: 1. Bastion Host: A bastion host is a dedicated server that acts as a secure gateway for remote access to internal network resources. Placing a bastion host in the DMZ provides an additional layer of security, as it separates external and internal networks. Remote access would be first directed to the bastion host, and only authorized users with the appropriate credentials and permissions would be able to access the internal resources from there. 2. Multi-Factor Authentication (MFA): MFA adds an extra layer of security by requiring users to provide multiple forms of authentication, such as a password and a one-time authentication code (e.g., from a mobile app or hardware token). This makes it more difficult for unauthorized individuals to gain access, even if they have the user's password.
upvoted 1 times
...
CoolCat22
12 months ago
Selected Answer: B
B Install a bastion host in the demilitarized zone (DMZ) and allow multi-factor authentication (MFA) access.
upvoted 1 times
...
jens23
1 year, 4 months ago
why on earth would anyone place a jump box to a DMZ? that's a pretty bad security practice. Use VPN, connect to jump host in an internal management network and from there manage the infrastructure.
upvoted 2 times
...
ded
1 year, 4 months ago
Bastion hosts are the bad practice nowadays.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
C. The question states that the employee travels globally. "You can access your website or server from anywhere in the world without worrying about changes to your IP address." https://www.paloaltonetworks.com/cyberpedia/what-is-dynamic-dns#:~:text=Dynamic%20DNS%2C%20or%20DDNS%2C%20is,changes%20to%20your%20IP%20address. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-DDNS-for-SSL-VPN/ta-p/194137
upvoted 1 times
...
Moose01
1 year, 6 months ago
B. is correct
upvoted 1 times
...
evenkeel
1 year, 10 months ago
I think DDNS is normally used in homes, not businesses. I think I with B. Configure Bastion host with Public IP and connect via SSH over the internet.
upvoted 1 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: B
I think B is correct. This is similar to a jump box.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...