A security administrator is documenting the secure network transit path for a remote system administrator to access a sensitive internal database server via a bastion host. Arrange the following network zones in order from the initial connection point (least secure/untrusted external) to the final destination (most secure internal target).
- 1External Public Internet
- 2Perimeter Screened Subnet (DMZ)
- 3Bastion Host Management Subnet
- 4Isolated Backend Database Zone
Cevap
The correct network path order from external origin to secure target is: External Public Internet, Perimeter Screened Subnet (DMZ), Bastion Host Management Subnet, and Isolated Backend Database Zone.
The proper administrative connection flow follows defense-in-depth segmentation principles: the remote session starts on the untrusted External Public Internet, enters the Perimeter Screened Subnet (DMZ), authenticates at the Bastion Host Management Subnet, and finally proxies through to the Isolated Backend Database Zone.
Adım Adım Çözüm
Anahtar Kavram
Bastion Host Jump Box and Network Zone Transit Sequence
Tahmini Süre:45s