CompTIA Network+ (N10-009)Network OperationsMedium
An administrator wants to allow remote engineers to access a segmented internal management network without exposing internal management interfaces directly to the internet. All remote sessions should first authenticate and be logged through a single hardened host before reaching internal devices. Which solution best meets this requirement?
- ASplit-tunnel VPN
- BReverse proxy for web traffic only
- CJump box (bastion host)
- DSite-to-site VPN
Show answer & explanationAnswer & explanation
Correct answer: C. Jump box (bastion host)
A jump box (bastion host) is a hardened, tightly monitored server that acts as the single access point into a secured network segment, forcing all remote administrative sessions through one controlled and logged host.
Why the other options are wrong
- A. A split-tunnel VPN controls which traffic goes through the tunnel but doesn't provide a centralized, hardened access checkpoint.
- B. A reverse proxy handles web traffic distribution, not general administrative remote access.
- D. Site-to-site VPN connects two networks continuously but doesn't provide individual session logging/control.
Jump Box / Bastion Host
A hardened server that serves as the single controlled entry point for administrators to access an isolated or sensitive network segment, enabling centralized authentication and logging.
- Reduces attack surface by limiting direct access to internal devices
- All administrative sessions pass through and are logged at the jump box
- Commonly used to access management VLANs or DMZs securely
Memory trick: Jump box = the drawbridge into the castle's inner keep.