CCISO (712-50) Executive Decision Simulation
Train your strategic thinking capabilities. This simulation tests your ability to evaluate business impact, apply governance frameworks, and make board-level cybersecurity decisions.
Executive Briefing
You are the CISO for OmniHealth, a global healthcare provider. The organization is rapidly expanding its telehealth operations, which requires onboarding multiple third-party medical billing and IT support vendors. These vendors need remote access to specific, highly sensitive internal systems.
The Enterprise Architecture team has presented a blueprint for a new remote access gateway. You must approve the architectural policy regarding where the primary jump box (bastion host) is placed in relation to the network boundaries.
Business Context
- Business Objective: Enable rapid, secure remote access for third-party vendors to maintain telehealth operational continuity.
- Risk Appetite: Extremely low tolerance for unauthorized lateral movement or healthcare data exposure (HIPAA/HITECH compliance).
- Architectural Mandate: Governance policies require strict defense-in-depth; untrusted traffic must be sanitized as far away from internal assets as possible.
Decision Scenario
The engineering team asks for your final policy approval on the placement of the bastion host. They have proposed several network segments, varying from deep within the protected zones to fully exposed on the edge.
You must select the architectural boundary that best aligns with the principle of maximum risk absorption and defense-in-depth.
Question
A bastion host should be placed:
Strategic Analysis
1. What is the real problem?
Allowing third-party remote access inherently introduces high risk. If an attacker compromises a vendor's credentials, they can leverage the remote access gateway. The problem is defining the failure boundary: if the gateway is breached, where does the attacker land?
2. Business vs. Security Perspective
The business requires seamless access for vendors. However, from a security governance perspective, untrusted third-party access must be assumed hostile. The architecture must force all external, untrusted connections to terminate as far away from the protected core as physically and logically possible.
3. Risk and Impact Analysis
If the bastion host is placed inside a trusted zone (or even deeply within a complex DMZ behind multiple rulesets), a compromise immediately bypasses critical layers of defense. Placing it at the absolute edge ensures that even if the host falls, the attacker still faces the full strength of the organization's perimeter firewalls and internal segmentation.
4. Why the correct answer (C) is BEST
Beyond the outer perimeter firewall represents the strategic posture of maximum risk absorption. A bastion host is a specially configured, highly hardened system explicitly designed to withstand attacks. By placing it beyond the outer perimeter, it acts as the true first line of defense. It scrubs, authenticates, and proxies traffic before that traffic is allowed to even touch the enterprise's primary perimeter firewall.
5. Why other options are weaker
- A (Inside the DMZ): While commonly implemented in traditional networks, placing it inside the DMZ still allows untrusted traffic to pass through the outer firewall. For high-assurance governance (as tested in CCISO), pushing the risk completely outside the perimeter is preferred.
- B (In-line with data center): This places a massive risk element too close to the core assets and creates a single point of failure that bottlenecks critical data center traffic.
- D (Gatekeeper to honeynet): A bastion host provides legitimate, highly secure administrative access. A honeynet is a deceptive environment. Mixing these purposes violates the governance principle of separation of duties.
Security architecture is not just about installing firewalls; it is the strategic definition of risk boundaries. A CISO must design networks assuming components will fail. The bastion host is designed to be a target. Therefore, governance dictates placing this "target" where its compromise will yield the lowest possible blast radius to the rest of the business—outside the trusted perimeter.
"Design your architecture not to prevent failure, but to dictate exactly where and how the failure will be contained."
Ready for the next scenario?
Master executive-level cybersecurity decision-making.
Explore more CCISO simulations