SY0-701 Question 211
Single answerSecure access service edge (SASE)A company has moved most of its workforce to remote and hybrid work. Employees now access SaaS applications directly from home networks, and the security team has noticed inconsistent policy enforcement, limited visibility into cloud application usage, and growing dependence on a legacy VPN concentrator back at headquarters. The company wants to reduce reliance on backhauling traffic through the data center while still applying centralized security controls and user-based access policies. Which solution would BEST address these requirements?
- A
Deploy a secure access service edge (SASE) platform to combine cloud-delivered networking and security controls for remote users and branch offices
- B
Expand the existing VPN concentrator infrastructure and force all remote traffic through the headquarters firewall stack for inspection
- C
Implement network access control (NAC) on the internal LAN to verify device posture before allowing office-based connections
- D
Use a jump server in the data center for all SaaS access so user traffic stays inside the corporate network boundary
Show answer and explanation
Correct answer: A
Explanation
The best answer is the SASE platform because the scenario specifically describes modern requirements that SASE was created to address: remote and hybrid workers, direct access to SaaS applications, centralized policy enforcement, visibility into cloud usage, and a desire to eliminate inefficient backhauling through a headquarters data center. In Security+ terms, SASE is a cloud-centric architecture that converges network connectivity and security services to support distributed users and devices. Industry guidance from sources such as Gartner and vendor/standards documentation consistently describes SASE as combining network and security functions delivered from the cloud, often including SWG, CASB, ZTNA, and firewall capabilities. By contrast, simply scaling VPNs keeps the older perimeter model in place and does not adequately address performance and policy consistency for cloud-first environments.
- A. Correct.
Correct. SASE is designed to deliver networking and security functions from the cloud, closer to users and devices, rather than forcing traffic back to a central data center. In this scenario, the company needs consistent policy enforcement for remote and hybrid workers, better visibility into SaaS usage, and less reliance on a legacy VPN hub-and-spoke model. A SASE approach aligns with those goals by integrating capabilities such as secure web gateway (SWG), cloud access security broker (CASB), zero trust network access (ZTNA), and firewall/security inspection into a cloud-delivered architecture. This allows identity-aware, policy-based access without unnecessary backhauling.
- B. Incorrect.
Incorrect. Expanding the legacy VPN concentrator may temporarily increase capacity, but it does not solve the architectural problem described in the scenario. Backhauling all remote traffic through headquarters often increases latency, creates bottlenecks, and makes SaaS access less efficient. It also continues dependence on perimeter-based inspection rather than moving to cloud-delivered, user-centric controls. This is a common misconception: more VPN capacity improves scale somewhat, but it does not provide the same cloud-native security and direct-to-cloud access benefits as SASE.
- C. Incorrect.
Incorrect. NAC can be useful for validating endpoint posture on a local network, such as checking whether devices are compliant before granting LAN access. However, the company's challenges involve remote users, SaaS access, centralized enforcement, and reducing data-center backhaul. NAC is primarily focused on local or internal network admission decisions and does not address cloud-delivered security inspection and distributed remote access needs in the way SASE does.
- D. Incorrect.
Incorrect. A jump server can help control administrative access to internal systems, but it is not an appropriate primary solution for securing general SaaS access by a remote workforce. Routing all SaaS access through a jump server would add complexity, reduce usability, and still preserve the older idea that traffic must stay within a central corporate boundary. The scenario calls for scalable, policy-driven, cloud-based security controls rather than funneling users through a single hosted system.