ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 368 - SY0-601 discussion

Report
Export

A security analyst received the following requirements for the deployment of a security camera solution:

* The cameras must be viewable by the on-site security guards.

+ The cameras must be able to communicate with the video storage server.

* The cameras must have the time synchronized automatically. * The cameras must not be reachable directly via the internet.

* The servers for the cameras and video storage must be available for remote maintenance via the company VPN.

Which of the following should the security analyst recommend to securely meet the remote connectivity requirements?

A.
Creating firewall rules that prevent outgoing traffic from the subnet the servers and cameras reside on
Answers
A.
Creating firewall rules that prevent outgoing traffic from the subnet the servers and cameras reside on
B.
Deploying a jump server that is accessible via the internal network that can communicate with the servers
Answers
B.
Deploying a jump server that is accessible via the internal network that can communicate with the servers
C.
Disabling all unused ports on the switch that the cameras are plugged into and enabling MAC filtering
Answers
C.
Disabling all unused ports on the switch that the cameras are plugged into and enabling MAC filtering
D.
Implementing a WAF to allow traffic from the local NTP server to the camera server
Answers
D.
Implementing a WAF to allow traffic from the local NTP server to the camera server
Suggested answer: B

Explanation:

A jump server is a system that is used to manage and access systems in a separate security zone. It acts as a bridge between two different security zones and provides a controlled and secure way of accessing systems between them12. A jump server can also be used for auditing traffic and user activity for real-time surveillance3. By deploying a jump server that is accessible via the internal network, the security analyst can securely meet the remote connectivity requirements for the servers and cameras without exposing them directly to the internet or allowing outgoing traffic from their subnet. The other options are not suitable because:

A. Creating firewall rules that prevent outgoing traffic from the subnet the servers and cameras reside on would not allow remote maintenance via the company VPN.

C. Disabling all unused ports on the switch that the cameras are plugged into and enabling MAC filtering would not prevent direct internet access to the cameras or servers.

D. Implementing a WAF to allow traffic from the local NTP server to the camera server would not address the remote connectivity requirements or protect the servers from internet access.

Reference:

1: https://www.thesecuritybuddy.com/network-security/what-is-a-jump-server/ 3:

https://www.ssh.com/academy/iam/jump-server 2: https://en.wikipedia.org/wiki/Jump_server

asked 02/10/2024
Tarnauceanu Diana
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first