Cisco CCNP Security Core (SCOR) 350-701Network SecurityEasy
A company is implementing a new security policy that requires all remote access to internal resources to use a secure, encrypted tunnel over the internet. The solution must support various client operating systems and provide strong authentication. Which technology best fits these requirements?
- ASite-to-site VPN
- BRemote-access VPN
- CDemilitarized Zone (DMZ)
- DNetwork Address Translation (NAT)
Show answer & explanationAnswer & explanation
Correct answer: B. Remote-access VPN
Remote-access VPNs are designed for individual users to securely connect to a private network from a remote location over the internet, providing encryption and strong authentication. Site-to-site VPNs connect entire networks, not individual users. NAT translates IP addresses. A DMZ is a network segment for public-facing servers.
Why the other options are wrong
- A. Site-to-site VPNs connect entire networks (e.g., branch office to headquarters), not individual remote users.
- C. A DMZ is a network segment used to host public-facing servers and does not provide remote access for individual users to internal resources.
- D. NAT translates IP addresses and does not provide secure encrypted tunnels for remote access.
Remote-Access VPN
A Remote-Access VPN (Virtual Private Network) allows individual users to establish a secure, encrypted connection to a private network from a remote location over a public network like the internet.
- Connects individual users.
- Provides secure tunnels (encryption).
- Supports various client OS via software.
Memory trick: VPNs are like secret tunnels; know who's using them.