SY0-701 exam dumps

SY0-701 practice question 209 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 209

Single answer

A company is replacing a legacy remote-access VPN concentrator used by traveling employees. The security team must support users connecting from hotel and airport Wi-Fi, minimize connection failures caused by NAT devices, and ensure all authentication and session data is encrypted in transit without requiring a full IPsec client configuration on unmanaged contractor laptops. Which solution best meets these requirements?

  1. A

    Deploy a clientless SSL/TLS VPN portal over HTTPS for remote access

  2. B

    Deploy an IPsec tunnel in transport mode and require contractors to manually configure phase 1 and phase 2 settings

  3. C

    Deploy a site-to-site IPsec VPN between the company firewall and each user's home router

  4. D

    Replace remote access with SD-WAN overlays directly from unmanaged endpoints to internal servers

Show answer and explanation

Correct answer: A

Explanation

The best answer is a clientless SSL/TLS VPN portal because the scenario emphasizes remote user access from untrusted public networks, NAT friendliness, and minimal endpoint configuration on unmanaged systems. TLS-based remote access over HTTPS is widely used because it traverses most firewalls and NAT devices more reliably than traditional IPsec configurations and avoids the overhead of configuring full VPN clients on every contractor endpoint. By contrast, IPsec transport mode is better suited to managed environments with coordinated configuration, and site-to-site IPsec is intended for network-to-network tunneling rather than roaming users. SD-WAN is valuable for branch and WAN connectivity, but it is not the most appropriate primary answer for this user remote-access use case. This aligns with common vendor guidance and best practices: use TLS-based remote access for browser-accessible applications and unmanaged endpoints, and use IPsec primarily for site-to-site links or managed full-tunnel remote-access deployments when client software and policy control are available.

  • A. Correct.

    Correct. A clientless SSL/TLS VPN portal uses HTTPS/TLS, which works well across NAT and public Wi-Fi environments because TCP 443 is commonly allowed outbound. It also reduces endpoint configuration requirements, making it appropriate for unmanaged contractor systems. This approach encrypts authentication and session traffic in transit and is a common solution for browser-based remote access to internal applications.

  • B. Incorrect.

    Incorrect. IPsec transport mode protects host-to-host traffic but does not provide the easiest user experience for unmanaged contractor devices. Requiring users to manually configure IKE/IPsec parameters increases operational complexity and support burden. In addition, traditional IPsec remote access can be more sensitive to NAT issues unless NAT traversal is properly supported and configured.

  • C. Incorrect.

    Incorrect. Site-to-site IPsec is designed to connect networks, not individual roaming users on hotel or airport Wi-Fi. It assumes a gateway-to-gateway relationship and would not be practical for traveling employees or contractors using various unmanaged devices and unknown networks.

  • D. Incorrect.

    Incorrect. SD-WAN is primarily used to manage and optimize connectivity between sites, data centers, and cloud environments. While some platforms include secure remote-access features, SD-WAN overlays from unmanaged endpoints directly to internal servers are not the standard or simplest answer to the stated remote-access requirement. The scenario is specifically focused on secure user remote access with minimal client configuration.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam