A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
Choose an answer
Tap an option to check your answer.
Correct answer: Implementing a bastion host.
Why this is the answer
Implementing a bastion host is the most secure method for providing administrative access while minimizing traffic through a security boundary. A bastion host is a specially hardened server that sits in a demilitarized zone (DMZ) and acts as a jump server, allowing administrators to connect to it first before accessing internal resources. This minimizes the attack surface by exposing only one hardened system to the internet, rather than multiple internal systems. Deploying a perimeter network (DMZ) is a component of this solution but doesn't, by itself, specify the secure access method. Installing a WAF (Web Application Firewall) protects web applications, not general administrative access to internal resources. Utilizing single sign-on (SSO) improves user convenience and can enhance authentication security, but it doesn't directly address minimizing traffic through the security boundary or providing a hardened jump point for administrative access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed