CompTIA Security+ (SY0-701)Security ArchitectureEasy

A network administrator wants to allow remote administrators to securely access internal servers without exposing those servers directly to the internet. All SSH sessions to internal hosts must first pass through a single, tightly monitored intermediary system. Which solution should the administrator deploy?

  1. AReverse proxy
  2. BLoad balancer
  3. CJump server
  4. DVLAN trunk
Show answer & explanation

Correct answer: C. Jump server

A jump server (bastion host) acts as a controlled, hardened gateway that administrators use to access internal systems, centralizing and monitoring all remote administrative access rather than exposing internal hosts directly.

Why the other options are wrong

  • A. A reverse proxy forwards client web requests to backend servers, not administrative SSH sessions.
  • B. A load balancer distributes traffic across servers for availability, not access control.
  • D. A VLAN trunk carries multiple VLANs between switches, unrelated to access control.

Jump Server (Bastion Host)

A hardened, monitored system that administrators must connect through to reach internal network resources, reducing direct exposure of internal hosts.

  • Centralizes and logs administrative access
  • Reduces attack surface of internal servers
  • Often placed in a DMZ or management network

Memory trick: One door in, watched by a guard.

More Security Architecture questions