Courseiva
Security Architecture →hardMultiple Choice

SY0-701 Security Architecture Practice Question

A multinational corporation is implementing a secure remote access solution for its employees. The security team requires that all remote sessions be encrypted, that users authenticate with multifactor authentication (MFA), and that the solution supports granular access control based on user identity and device posture. Which of the following technologies best meets these requirements?

⚠ Common exam trap

The trap here is assuming that any VPN with MFA provides granular access control based on device posture, when in fact traditional VPNs often grant broad network access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Software-defined perimeter (SDP) with zero trust network access (ZTNA).

The correct answer is SDP with ZTNA. It uniquely combines encryption, MFA, and granular, context-aware access control based on user identity and device posture. Other options may provide encryption and authentication but lack the dynamic, identity-centric access control that the scenario demands. SDP with ZTNA is designed for zero trust environments, making it the most suitable choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote Desktop Protocol (RDP) gateway with Network Level Authentication (NLA).

    Why it's wrong here

    An RDP gateway with NLA encrypts sessions and requires authentication before establishing a connection, but it is specific to RDP and does not provide granular access control based on user identity and device posture across various applications. It also may not support MFA natively without additional configuration. Therefore, it is not the best solution for the broad requirements.

  • ✓

    Software-defined perimeter (SDP) with zero trust network access (ZTNA).

    Why this is correct

    SDP with ZTNA encrypts all sessions, enforces MFA, and provides granular, identity- and context-aware access control. It creates a logical perimeter around applications, granting access only after verifying user identity and device posture. This directly meets the requirements for encryption, MFA, and dynamic access control based on user and device attributes, making it the best fit.

  • ✗

    SSL VPN with split tunneling and a captive portal.

    Why it's wrong here

    An SSL VPN with split tunneling encrypts traffic and can integrate MFA, but split tunneling allows simultaneous access to the internet and corporate network, potentially bypassing security controls. A captive portal is primarily for guest access and does not provide granular access control based on device posture. Thus, it does not fully satisfy the requirement for identity- and posture-based access control.

  • ✗

    IPsec VPN with pre-shared keys and static routing.

    Why it's wrong here

    An IPsec VPN with pre-shared keys encrypts traffic and can support MFA if integrated with an authentication server, but it typically does not provide granular access control based on user identity and device posture without additional components. Pre-shared keys are also less secure than certificate-based authentication. The solution lacks the dynamic, identity-aware access control required, making it insufficient for the scenario.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.