CompTIA Security+ Exam Prep

Category - Communication

What is the first line of defense for a network’s security and is another name for a locked-down system?
  1. Firewall Architecture
  2. Dual-homed Firewall
  3. Bastion Host
  4. Screened Host
Explanation
Answer: C - Bastion Host is the first line of defense for a network’s security and is another name for a locked-down system. A bastion host is usually a highly-exposed device because it is the first line in a network’s security and its existence is known on the Internet. This means the device must be extremely secure. A bastion host is not tied to firewall software and activities. It is just a system that is properly locked down.

Any system that resides within the DMZ should be installed on a bastion host since it is closer to the Internet and most likely closer to those who would like to do it harm If firewall software is not installed on a locked-down operating system.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz