Systems Security Certified Practitioner – SSCP – Question0987

What is the main characteristic of a bastion host?

A.
It is located on the internal network.
B. It is a hardened computer implementation
C. It is a firewall.
D. It does packet filtering.

Correct Answer: B

Explanation:

A bastion host is a special purpose computer on a network specifically designed and configured to withstand attack. The computer hosts a single application, for example a proxy server, and all other services are removed or limited to reduce the threat to the computer. It is hardened in this manner primarily due to its location and purpose, which is either on the outside of the firewall or in the DMZ and usually involves access from untrusted networks or computers.
References: http://en.wikipedia.org/wiki/Bastion_host