N10-009 Question 131
Single answerSecure Access Secure Edge (SASE)/Security Service Edge (SSE)A company has moved most of its applications to SaaS platforms and now supports a large remote workforce. Users currently connect through a legacy VPN concentrator at headquarters, but IT is seeing frequent performance complaints because all traffic is backhauled through the data center before reaching cloud services. Management wants to improve user access to SaaS applications while still enforcing consistent web filtering, data protection policies, and access controls for users regardless of location. Which solution would BEST meet these requirements?
- A
Replace the VPN concentrator with a larger on-premises firewall and continue routing all remote traffic through headquarters
- B
Implement a SASE platform that delivers cloud-based networking and security policy enforcement close to the user
- C
Deploy a dedicated MPLS circuit from each employee home office to the corporate data center
- D
Publish all SaaS applications through a port-forwarding rule on the edge router to reduce VPN dependence
Show answer and explanation
Correct answer: B
Explanation
The best answer is to implement a SASE platform. In real-world environments with many remote users and heavy SaaS adoption, sending all traffic through a central VPN gateway often causes latency and poor user experience because of traffic backhauling. SASE addresses this by combining network access and security capabilities in a cloud-delivered model, allowing users to connect to a nearby point of presence while the organization still applies consistent security policies. Depending on the vendor design, these controls may include functions associated with Security Service Edge (SSE), such as secure web gateway (SWG), cloud access security broker (CASB), and zero trust network access (ZTNA), along with broader connectivity capabilities under the SASE umbrella. This approach is consistent with common industry guidance from Gartner's SASE framework and zero-trust best practices such as NIST SP 800-207, which emphasize identity-aware, policy-based access rather than relying only on perimeter-based VPN designs.
- A. Incorrect.
This would increase on-premises capacity, but it would not solve the core design issue of backhauling remote-user traffic through headquarters. SASE is intended to reduce reliance on centralized security stacks by moving security inspection and access policy enforcement closer to users and cloud resources. A larger firewall may temporarily improve throughput, but it does not provide the distributed, cloud-delivered access model the scenario requires.
- B. Correct.
This is correct. Secure Access Service Edge (SASE) combines WAN or connectivity functions with cloud-delivered security services so users can connect to nearby provider points of presence instead of hairpinning traffic through a central office. In this scenario, that improves SaaS performance for remote users while still allowing centralized enforcement of policies such as secure web gateway filtering, zero-trust network access controls, and data protection functions. This aligns directly with the goal of location-independent, policy-based access to cloud applications.
- C. Incorrect.
MPLS is generally used to provide reliable private WAN connectivity between business sites, not individual employee homes at scale. It would also be costly and operationally impractical for a large remote workforce. More importantly, MPLS does not inherently provide the cloud-delivered security controls and distributed access enforcement that the company wants.
- D. Incorrect.
Port forwarding on an edge router is not an appropriate way to secure access to SaaS applications, because SaaS applications are already hosted by third-party providers and are normally accessed over the internet using the provider's published services. Exposing internal services with port forwarding would create unnecessary security risk and would not address remote-user policy enforcement, web filtering, or data protection needs.