CompTIA Network+ (N10-009)Network OperationsMedium

An administrator wants to allow remote engineers to access a segmented internal management network without exposing internal management interfaces directly to the internet. All remote sessions should first authenticate and be logged through a single hardened host before reaching internal devices. Which solution best meets this requirement?

  1. ASplit-tunnel VPN
  2. BReverse proxy for web traffic only
  3. CJump box (bastion host)
  4. DSite-to-site VPN
Show answer & explanation

Correct answer: C. Jump box (bastion host)

A jump box (bastion host) is a hardened, tightly monitored server that acts as the single access point into a secured network segment, forcing all remote administrative sessions through one controlled and logged host.

Why the other options are wrong

  • A. A split-tunnel VPN controls which traffic goes through the tunnel but doesn't provide a centralized, hardened access checkpoint.
  • B. A reverse proxy handles web traffic distribution, not general administrative remote access.
  • D. Site-to-site VPN connects two networks continuously but doesn't provide individual session logging/control.

Jump Box / Bastion Host

A hardened server that serves as the single controlled entry point for administrators to access an isolated or sensitive network segment, enabling centralized authentication and logging.

  • Reduces attack surface by limiting direct access to internal devices
  • All administrative sessions pass through and are logged at the jump box
  • Commonly used to access management VLANs or DMZs securely

Memory trick: Jump box = the drawbridge into the castle's inner keep.

More Network Operations questions