ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 447 - SY0-601 discussion

Report
Export

An organization routes all of its traffic through a VPN Most users are remote and connect into a corporate data center that houses confidential information There is a firewall at the internet border, followed by a DLP appliance, the VPN server and the data center itself Which of the following is the weakest design element?

A.
The DLP appliance should be integrated into a NGFW.
Answers
A.
The DLP appliance should be integrated into a NGFW.
B.
Split-tunnel connections can negatively impact the DLP appliance's performance.
Answers
B.
Split-tunnel connections can negatively impact the DLP appliance's performance.
C.
Encrypted VPN traffic will not be inspected when entering or leaving the network.
Answers
C.
Encrypted VPN traffic will not be inspected when entering or leaving the network.
D.
Adding two hops in the VPN tunnel may slow down remote connections
Answers
D.
Adding two hops in the VPN tunnel may slow down remote connections
Suggested answer: C

Explanation:

VPN (Virtual Private Network) traffic is encrypted to protect its confidentiality and integrity over the internet. However, this also means that it cannot be inspected by security devices or tools when entering or leaving the network, unless it is decrypted first. This can create a blind spot or a vulnerability for the network security posture, as malicious traffic or data could bypass detection or prevention mechanisms by using VPN encryption

asked 02/10/2024
Luis Hernaiz
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first