350-201 Question 63
Select 3You are tasked with evaluating the security posture of a corporate network. After conducting an assessment, you discover that the company lacks Multi-Factor Authentication (MFA) for remote access, uses outdated encryption protocols for VPN connections, and has no centralized log management. Which of the following recommendations should you prioritize to address the security gaps effectively?
- A
Implement Multi-Factor Authentication (MFA) for all remote access users.
- B
Upgrade to modern encryption protocols, such as AES-256, for VPN connections.
- C
Deploy a centralized log management solution to improve incident detection and response.
- D
Increase network bandwidth to handle additional remote user traffic.
- E
Disable remote access entirely to eliminate associated risks.
Show answer and explanation
Correct answers: A, B, C
Explanation
The identified security gaps include weak authentication for remote access, insecure VPN encryption, and lack of centralized logging. Addressing these gaps by implementing MFA, upgrading encryption protocols, and deploying centralized log management will collectively improve the organization’s security posture while maintaining usability and operational efficiency. Increasing bandwidth or disabling remote access does not directly resolve the security issues and may introduce operational challenges.
- A. Correct.
Implementing Multi-Factor Authentication (MFA) significantly enhances the security of remote access by requiring a second factor for authentication, reducing the risk of unauthorized access.
- B. Correct.
Upgrading to modern encryption protocols ensures secure communication over VPNs, mitigating the risk of data interception or compromise.
- C. Correct.
Deploying a centralized log management solution improves visibility into network activity and supports faster detection and response to security incidents.
- D. Incorrect.
Increasing network bandwidth is not directly related to addressing the identified security gaps and does not mitigate the risks associated with the current vulnerabilities.
- E. Incorrect.
Disabling remote access entirely is impractical for most organizations and does not align with enabling secure and productive workflows.