An organization wants to implement a secure solution for remote users. The users handle sensitive PHI on a regular basis and need to access an internally developed corporate application. Which of the following best meet the organization's security requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Jump server, VPN.
Why this is the answer
A VPN (Virtual Private Network) provides a secure, encrypted tunnel over an untrusted network (like the internet) to the corporate network, ensuring confidentiality and integrity for PHI. This is essential for remote users handling sensitive data. A jump server (or bastion host) acts as an intermediary, controlled access point to internal resources. Users connect to the jump server, which then allows access to the sensitive application, adding an extra layer of security and logging capabilities, crucial for protecting PHI. MFA (Multi-Factor Authentication) is a strong security control but doesn't, by itself, secure the connection or provide an access intermediary. A WAF (Web Application Firewall) protects web applications from attacks, but the question specifies an internally developed corporate application, not necessarily a web-facing one, and it doesn't secure the remote connection itself. A local administrative password is a device-level control, not a solution for secure remote access to corporate resources. A perimeter network (DMZ) is for exposing services to external users, not for securing remote user access to internal applications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed