企業のセキュリティ チームは、最新のサイバー脅威から会社のネットワークとアプリケーションをより適切に保護するための新しいセキュリティ アーキテクチャを調査しています。この会社には、完全にリモート ワーカーがいます。ソリューションは、高度な冗長性を備え、統合されたソフトウェア ベースのファイアウォールを使用してユーザーが VPN に接続できるようにする必要があります。次のソリューションのうち、これらの要件を満たすものはどれですか。
正解:C
The requirements point to a cloud-delivered, remote-user-first architecture that provides secure connectivity and security controls as an integrated service. Secure Access Service Edge (SASE) matches this because it combines remote connectivity capabilities (often replacing or modernizing traditional VPN approaches) with cloud-based security services, including firewalling, in a way that supports distributed users and resilient global access. The Study Guide explicitly states: "Secure Access Service Edge (SASE... ) combines virtual private networks, SD-WAN, and cloud-based security tools like firewalls, cloud access security brokers (CASBs), and zero-trust networks to provide secure access for devices regardless of their location." This directly aligns with a fully remote workforce ("regardless of their location"), VPN capability, and an integrated firewall ("cloud-based security tools like firewalls").
Why the other options don't fit as well: IPS is a specific protective control, not an end-to-end remote access architecture; SIEM is for log aggregation/correlation and monitoring, not VPN + firewall delivery; and CASB is a component used to enforce cloud policy, but the guide distinguishes it as a policy enforcement point rather than a full connectivity + firewall architecture: "A CASB is a policy enforcement point..." . Therefore, SASE is the best match.
References: Sybex CompTIA Security+ Study Guide (SY0-701) - SASE definition and included capabilities (also duplicated in ).