CompTIA Security+ (SY0-701)Security ArchitectureEasy
A network administrator wants to allow remote administrators to securely access internal servers without exposing those servers directly to the internet. All SSH sessions to internal hosts must first pass through a single, tightly monitored intermediary system. Which solution should the administrator deploy?
- AReverse proxy
- BLoad balancer
- CJump server
- DVLAN trunk
Show answer & explanationAnswer & explanation
Correct answer: C. Jump server
A jump server (bastion host) acts as a controlled, hardened gateway that administrators use to access internal systems, centralizing and monitoring all remote administrative access rather than exposing internal hosts directly.
Why the other options are wrong
- A. A reverse proxy forwards client web requests to backend servers, not administrative SSH sessions.
- B. A load balancer distributes traffic across servers for availability, not access control.
- D. A VLAN trunk carries multiple VLANs between switches, unrelated to access control.
Jump Server (Bastion Host)
A hardened, monitored system that administrators must connect through to reach internal network resources, reducing direct exposure of internal hosts.
- Centralizes and logs administrative access
- Reduces attack surface of internal servers
- Often placed in a DMZ or management network
Memory trick: One door in, watched by a guard.