SY0-701 exam dumps

SY0-701 practice question 210 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 210

Single answerSecure access service edge (SASE)

A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications, internal web applications, and cloud resources directly from home networks instead of through the corporate office. The security team wants to reduce reliance on backhauling traffic through the data center, apply consistent access policies based on user identity and device posture, and inspect traffic closer to the user. Which solution best meets these requirements?

  1. A

    Deploy a secure access service edge (SASE) platform that combines cloud-delivered networking and security services with identity-based access controls

  2. B

    Expand the existing site-to-site VPN concentrators in the primary data center and require all remote users to tunnel all traffic through headquarters

  3. C

    Implement network access control (NAC) on the corporate LAN so remote users are checked for compliance when they connect to office switches

  4. D

    Replace the perimeter firewall with a higher-throughput model and continue routing remote access traffic through the corporate network

Show answer and explanation

Correct answer: A

Explanation

The best answer is the SASE platform because the scenario specifically calls for cloud-delivered security and networking for remote and hybrid users, reduced backhaul to a central site, and policy enforcement based on user identity and device posture. These are core SASE use cases. Industry guidance such as Gartner's definition of SASE and zero trust best practices align with this approach: move security controls closer to the user and application, and make access decisions using identity, context, and posture rather than relying only on a traditional network perimeter. In Security+ terms, SASE is a modern architecture that helps secure access to SaaS, cloud, and private applications for a distributed workforce while improving scalability and user experience.

  • A. Correct.

    Correct. SASE is designed for organizations with distributed users, devices, and applications. It converges network connectivity and security functions into a cloud-delivered model, commonly including capabilities such as secure web gateway (SWG), cloud access security broker (CASB), firewall as a service (FWaaS), and zero trust network access (ZTNA). This supports identity-based policy enforcement, device-aware access decisions, and traffic inspection at points of presence closer to users, helping avoid the latency and operational burden of backhauling traffic through a central data center.

  • B. Incorrect.

    Incorrect. Sending all remote-user traffic through centralized VPN concentrators is the traditional approach, but it directly conflicts with the requirement to reduce backhauling. While VPNs can provide encrypted remote access, they typically do not natively provide the full cloud-delivered, identity-centric, and distributed security architecture associated with SASE. This option may also create bottlenecks and poorer user experience for SaaS and cloud access.

  • C. Incorrect.

    Incorrect. NAC is useful for controlling device access on local enterprise networks, such as checking posture before allowing a device onto a corporate LAN or WLAN. However, it does not solve the main problem in this scenario: providing cloud-delivered security inspection and identity-based access for remote users connecting directly to SaaS, internal apps, and cloud resources from home networks.

  • D. Incorrect.

    Incorrect. Upgrading a perimeter firewall may improve throughput at the edge of the corporate network, but it still assumes a centralized perimeter model. That does not address the company's need to inspect traffic closer to remote users or reduce dependence on routing remote traffic through headquarters. It also does not by itself provide the broader SASE framework of integrated cloud networking and security services.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam