N10-009 exam dumps

N10-009 practice question 130 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 130

Single answerSecure Access Secure Edge (SASE)/Security Service Edge (SSE)

A company has moved most of its applications to SaaS platforms and now has a largely remote workforce. Users connect from home networks, hotels, and customer sites. The security team wants to stop backhauling all user traffic through the data center VPN because it is causing latency and poor application performance. They also want consistent enforcement of web filtering, zero-trust access to private applications, and cloud-based inspection regardless of user location. Which solution best meets these requirements?

  1. A

    Deploy a SASE platform that combines cloud-delivered networking and security controls close to the user

  2. B

    Expand the existing site-to-site VPN concentrators in the data center and require all remote users to tunnel all traffic back to headquarters

  3. C

    Install host-based antivirus on all laptops and allow direct user access to applications without centralized policy enforcement

  4. D

    Replace the edge firewall with a higher-throughput appliance at headquarters and continue routing branch and remote traffic through the main office

Show answer and explanation

Correct answer: A

Explanation

The best answer is the SASE platform because the scenario specifically calls for cloud-delivered security and access controls for remote users without data-center backhaul. SASE, or Secure Access Service Edge, is a framework that combines network connectivity and security services into a cloud-delivered architecture. For Network+ purposes, the important practical distinction is that SASE is well suited for remote users, branch offices, and cloud-first organizations because it applies policy near the user and the application. SSE, or Security Service Edge, focuses on the security-services portion of this model, typically including capabilities such as secure web gateway (SWG), cloud access security broker (CASB), and zero-trust network access (ZTNA), while SASE adds the networking component as well. Vendor and industry documentation, including Gartner's definitions and common enterprise best practices, consistently describe SASE as a way to reduce latency, improve user experience, and enforce consistent security for distributed workforces accessing SaaS and private applications.

  • A. Correct.

    Correct. SASE is designed for organizations with distributed users, cloud applications, and branch/remote connectivity needs. It converges WAN/network connectivity with cloud-delivered security services so traffic can be inspected and policy can be enforced closer to the user instead of forcing backhaul through a central data center. In practice, a SASE approach can incorporate capabilities such as secure web gateway functionality, cloud access security broker features, firewall as a service, and zero-trust network access for private applications. This directly addresses the company's goals of reducing latency, supporting remote users, and applying consistent security controls regardless of location.

  • B. Incorrect.

    Incorrect. This approach continues the exact problem described in the scenario: backhauling remote-user traffic through the data center. While adding VPN capacity may help with scale, it does not solve the performance issue caused by sending SaaS-bound traffic to headquarters first. It also does not align with the move toward cloud-delivered security and location-independent policy enforcement that SASE/SSE architectures are intended to provide.

  • C. Incorrect.

    Incorrect. Endpoint antivirus is useful, but it does not provide the centralized, identity-aware access control and cloud-based traffic inspection required here. Allowing direct access without centralized enforcement would weaken policy consistency and visibility. This option reflects the misconception that endpoint protection alone can replace network/security edge controls for SaaS access and zero-trust connectivity.

  • D. Incorrect.

    Incorrect. A larger on-premises firewall may improve throughput at headquarters, but it still depends on a centralized security model that sends user and branch traffic to the main office. That does not solve the remote-user latency problem for SaaS applications and does not provide the cloud-delivered, distributed enforcement model associated with SASE. It is a traditional perimeter scaling response to a problem better solved with a modern distributed edge architecture.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam