Security+ Lesson

Network Security Appliances for Security+

Last updated: 6/10/2026

Short answer

Network security appliances are selected by role. A jump server controls administrative access. Instead of allowing administrators to connect directly from user networks to production servers, the organization requires them to authenticate to a hardened intermediary. The jump server can be monitored, logged, restricted, and placed in a management path. This reduces attack surface on management interfaces and creates a central point for administrative access control. It does not replace identity governance or privileged access management, but it supports secure infrastructure design.

Why it appears on the exam

SY0-701 3.2: Recognize the infrastructure roles of jump servers, proxies, intrusion prevention system (IPS)/intrusion detection system (IDS), load balancers, sensors, and related appliances.

Key concepts

Concept 1

Required terms

Jump server: a hardened intermediary system used to access administrative interfaces in another zone, reducing direct management exposure. Proxy server: an intermediary that makes requests on behalf of clients or services, often enforcing policy, filtering content, hiding internal details, caching, or logging access. IPS: intrusion prevention system, a security appliance or function that detects suspicious traffic and can actively block, reset, or prevent it. IDS: intrusion detection system, a security appliance or function that detects suspicious traffic or activity and alerts without necessarily blocking.

Example

Administrators must reach database servers in a restricted zone without exposing SSH or RDP from general user networks. A jump server is the appropriate intermediary.

Concept 2

How Network Security Appliances works

Network security appliances are selected by role. A jump server controls administrative access. Instead of allowing administrators to connect directly from user networks to production servers, the organization requires them to authenticate to a hardened intermediary. The jump server can be monitored, logged, restricted, and placed in a management path. This reduces attack surface on management interfaces and creates a central point for administrative access control. It does not replace identity governance or privileged access management, but it supports secure infrastructure design.

Example

Users' outbound web traffic must be logged and filtered before going to the Internet. A proxy server fits because it brokers requests and applies policy.

Concept 3

Common confusion

Learners often confuse IDS and IPS. The shortest correction is detection versus prevention: IDS alerts, IPS can block. Learners also sometimes choose a proxy for any security function. A proxy is specifically an intermediary for requests; it is not the same as a jump server for administration or a sensor for telemetry.

Example

The organization wants to alert on suspicious traffic while first tuning rules. An IDS or passive sensor is appropriate because the scenario emphasizes detection without blocking.

Concept 4

What to recognize

Match jump server to controlled administrative access across zones; Match proxy server to intermediary request handling, policy, filtering, logging, or internal server shielding; Choose IDS for alerting without direct blocking; Choose IPS for active prevention of malicious traffic.

Example

Malicious traffic must be stopped before reaching a web server. An IPS is a better fit than IDS because prevention is required.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A security team sees this situation: Administrators must reach database servers in a restricted zone without exposing SSH or RDP from general user networks. A jump server is the appropriate intermediary. Which concept applies?

Q2.Read this Security+ situation: Users' outbound web traffic must be logged and filtered before going to the Internet. A proxy server fits because it brokers requests and applies policy. What is the best match?

Q3.A Security+ scenario describes this situation: Malicious traffic must be stopped before reaching a web server. An IPS is a better fit than IDS because prevention is required. Which answer fits best?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8