exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 108 discussion

Actual exam question from CompTIA's CS0-002
Question #: 108
Topic #: 1
[All CS0-002 Questions]

A cybersecurity analyst needs to rearchitect the network using a firewall and a VPN server to achieve the highest level of security. To BEST complete this task, the analyst should place the:

  • A. firewall behind the VPN server.
  • B. VPN server parallel to the firewall
  • C. VPN server behind the firewall.
  • D. VPN on the firewall.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
I_heart_shuffle_girls
Highly Voted 4 years, 5 months ago
I believe C is the correct answer.
upvoted 21 times
Obi_Wan_Jacoby
4 years, 5 months ago
I concur with C
upvoted 9 times
...
...
Adonist
Highly Voted 2 years, 9 months ago
Selected Answer: D
D is correct. If you ever set up a firewall and VPN in any company you would know the Firewall is usually the VPN server and it relays the authentication.
upvoted 6 times
...
RobV
Most Recent 1 year, 6 months ago
Selected Answer: C
C. VPN server behind the firewall.
upvoted 1 times
...
Pavel019846457
1 year, 8 months ago
Selected Answer: C
C looks the most reasonable.
upvoted 1 times
...
chaddman
1 year, 8 months ago
Selected Answer: C
This is the most secure configuration among the provided options. The firewall will filter incoming and outgoing traffic, allowing only legitimate traffic to reach the VPN server. This setup provides an additional layer of security to the VPN server and the internal network.
upvoted 1 times
...
asdDD12
2 years, 2 months ago
Selected Answer: D
The provided answer is correct. When the VPN server is on the firewall the firewall itself works before the VPN and after the VPN, which provides highest level of security.
upvoted 3 times
...
kiduuu
2 years, 2 months ago
Selected Answer: C
By placing the VPN server behind the firewall, all incoming and outgoing traffic is inspected by the firewall before it reaches the VPN server. This setup provides an additional layer of security, as the firewall can block any unauthorized traffic before it reaches the VPN server, and the VPN server only allows authenticated users to connect to the network.
upvoted 2 times
heinzelrumpel
1 year, 11 months ago
The same is achieved with answer D. Every Packet reaching the FW will be inspected, so is every outgoing packet. There is no extra layer of security when placing the VPN behind the FW. I am going with D
upvoted 3 times
...
...
2Fish
2 years, 3 months ago
Agree. C provides the most security. Even though many firewalls contain VPN features these days, this may submit the firewall to more attacks.
upvoted 1 times
...
CatoFong
2 years, 4 months ago
Selected Answer: C
C. is for correct
upvoted 1 times
...
CyberNoob404
2 years, 5 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
Mr_BuCk3th34D
2 years, 6 months ago
I will go with C, VPN server behind FW, and for a simple reason: it is talking about a VPN Server to stablish the remote connectivity, if the FW itself was supposed to be the gateway one could argue that VPN at the firewall would be the correct answer, but I agree this is outdated since companies rarely use specific purpose-built VPN servers nowadays.
upvoted 1 times
...
lordguck
2 years, 7 months ago
C: The traditional answer is "VPN server behind FW". Personally I think this is outdated for some time now. A VPN Server on a FW offers severe advantages (solution by one provider, central management, packet inspection of VPN connections, FW rules applied to VPN connections, geofencing ...) which outweight the drawbacks at least in small and medium sized companies.
upvoted 2 times
...
Weezyfbaby
2 years, 9 months ago
Selected Answer: C
The most common place for a VPN Server is behind the firewall, often in a DMZ with mail servers, Web servers, database servers, and so on. The advantage of this placement is that it fits cleanly into the network’s current security infrastructure. Also, the administrator is already familiar with how to route traffic through the firewall and only has to become familiar with the ports needed by the VPN server. https://www.techrepublic.com/article/configuring-vpn-connections-with-firewalls/#:~:text=As%20I%20mentioned%20above%2C%20the,database%20servers%2C%20and%20so%20on.
upvoted 1 times
...
Laudy
2 years, 10 months ago
Selected Answer: C
VPN Servers are almost exclusively internal to the Firewall.
upvoted 1 times
...
sn30
2 years, 10 months ago
Selected Answer: C
Best to achieve the highest security, has to be C
upvoted 1 times
...
Adonist
2 years, 11 months ago
I would go with D here. I've configured many firewalls and VPN and usually the VPN is on the firewall itself. Unless your VPN server will be on a host (like OpenVPN, Strongswan or even Windows VPN).
upvoted 4 times
...
FrancisBakon
2 years, 11 months ago
I have never seen a VPN infront of firewall. At most you have a FW->vpn->fw If you have an exposed public open vpn, chances of getting compromised are higher than behind the FW
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...