Which of the following is an important requirement when designing a secure remote access system?
Correct Answer: C
An important requirement when designing a secure remote access system is to ensure that logging and audit controls are included. A remote access system is a system that allows users or devices to access or connect to a network or a system from a remote location, such as the internet or a public network. A remote access system can provide various benefits, such as convenience, mobility, or productivity, for the users or devices that need to access or connect to the network or system from anywhere and anytime. However, a remote access system can also pose various security risks, such as unauthorized access, data leakage, or malware infection, for the network or system that is accessed or connected by the remote users or devices. Therefore, a remote access system should be designed and implemented with security in mind, by following various security principles, standards, or best practices. An important requirement when designing a secure remote access system is to ensure that logging and audit controls are included. Logging and audit controls are security mechanisms or functions that record, monitor, and analyze the activities, events, or transactions that occur on the remote access system, such as the authentication, authorization, encryption, or communication processes. Logging and audit controls can help to ensure the security of the remote access system, by providing the evidence, accountability, and traceability of the remote access system, as well as by detecting, preventing, or responding to any security incidents, anomalies, or violations that may occur on the remote access system. Configuring a Demilitarized Zone (DMZ) to ensure that user and service traffic is separated, providing privileged access rights to computer files and systems, or reducing administrative overhead through password self service are not the important requirements when designing a secure remote access system, as they are either more related to the network architecture, access management, or administration processes, rather than the logging and audit processes. References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 6: Secure Network Architecture and Securing Network Components, page 372; CISSP Official (ISC)2 Practice Tests, Third Edition, Domain 4: Communication and Network Security, Question 4.12, page 188.