CAS-004 Security Architecture Practice Question
A security architect is designing a network for a hospital that must keep its electronic health record (EHR) servers completely isolated from the internet while still allowing a small group of vendors to perform remote maintenance. The vendors use laptops that are not managed by the hospital. The architect proposes a jump host architecture. Which of the following designs best satisfies the requirement while minimizing risk?
⚠ Common exam trap
The trap here is assuming that any remote access method, such as a VPN or reverse proxy, provides the same isolation and auditability as a properly placed jump host with session recording.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a hardened jump host in a screened subnet, require vendor laptops to connect through a VPN with MFA, and then RDP to the EHR servers from the jump host after session recording is enabled.
The correct design uses a jump host in a screened subnet, VPN with MFA, and RDP with session recording. This combination isolates the EHR servers, authenticates the unmanaged vendor laptops, and provides an auditable path for maintenance. The other options either place the jump host on the protected VLAN, expose RDP directly, or use a reverse proxy that does not support direct server maintenance, all of which weaken isolation or control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish the EHR servers through a reverse proxy with client certificate authentication, and let vendors connect directly to the EHR web interface without a jump host.
Why it's wrong here
A reverse proxy with client certificates can secure a web application, but it does not provide the isolated, recorded administrative session needed for maintenance tasks that require direct server access. It also exposes the EHR servers to the same network path as the proxy, weakening the isolation goal. The scenario requires vendor maintenance, not just web access, so this design does not meet the requirement.
- ✓
Deploy a hardened jump host in a screened subnet, require vendor laptops to connect through a VPN with MFA, and then RDP to the EHR servers from the jump host after session recording is enabled.
Why this is correct
This design places the jump host in a screened subnet so it is reachable from the internet, but the EHR servers remain on an isolated internal segment. Requiring VPN with MFA authenticates the unmanaged vendor laptops, and RDP from the jump host provides a controlled, recorded session. Session recording gives the hospital an audit trail of every vendor action, which is essential for compliance and incident response.
- ✗
Deploy a jump host directly on the same VLAN as the EHR servers, allow vendors to connect to it over RDP from the internet after authenticating with a local account, and disable session logging to protect vendor privacy.
Why it's wrong here
Placing the jump host on the same VLAN as the EHR servers removes a layer of segmentation, so a compromised jump host gives direct lateral access to the records. Allowing RDP from the internet exposes the service to brute-force and exploitation. Disabling session logging eliminates the audit trail needed to investigate unauthorized vendor activity, which is unacceptable for regulated health data.
- ✗
Create a site-to-site IPsec tunnel from each vendor's office to the EHR VLAN, and allow the vendors to use their own remote administration tools directly against the EHR servers.
Why it's wrong here
A site-to-site tunnel from the vendor office does not authenticate the individual unmanaged laptops, and it extends the hospital network to the vendor premises. Allowing vendors to run their own tools directly against the EHR servers bypasses the centralized control and recording provided by a jump host. This design increases the attack surface and fails to isolate the EHR servers from the internet and from vendor endpoints.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.