CCISO (712-50) Executive Decision Simulation

Train your strategic thinking capabilities. This simulation tests your ability to evaluate business impact, apply governance frameworks, and make board-level cybersecurity decisions.

Executive Briefing

You are the CISO for OmniHealth, a global healthcare provider. The organization is rapidly expanding its telehealth operations, which requires onboarding multiple third-party medical billing and IT support vendors. These vendors need remote access to specific, highly sensitive internal systems.

The Enterprise Architecture team has presented a blueprint for a new remote access gateway. You must approve the architectural policy regarding where the primary jump box (bastion host) is placed in relation to the network boundaries.

Business Context

Decision Scenario

The engineering team asks for your final policy approval on the placement of the bastion host. They have proposed several network segments, varying from deep within the protected zones to fully exposed on the edge.

You must select the architectural boundary that best aligns with the principle of maximum risk absorption and defense-in-depth.

Question

A bastion host should be placed:

Executive Hint: Think about the purpose of a bastion host from a risk-absorption perspective. Should the untrusted traffic interact with your perimeter firewalls first, or should the bastion host act as the absolute outermost boundary to scrub traffic before it ever touches your enterprise perimeter?

Strategic Analysis

1. What is the real problem?

Allowing third-party remote access inherently introduces high risk. If an attacker compromises a vendor's credentials, they can leverage the remote access gateway. The problem is defining the failure boundary: if the gateway is breached, where does the attacker land?

2. Business vs. Security Perspective

The business requires seamless access for vendors. However, from a security governance perspective, untrusted third-party access must be assumed hostile. The architecture must force all external, untrusted connections to terminate as far away from the protected core as physically and logically possible.

3. Risk and Impact Analysis

If the bastion host is placed inside a trusted zone (or even deeply within a complex DMZ behind multiple rulesets), a compromise immediately bypasses critical layers of defense. Placing it at the absolute edge ensures that even if the host falls, the attacker still faces the full strength of the organization's perimeter firewalls and internal segmentation.

4. Why the correct answer (C) is BEST

Beyond the outer perimeter firewall represents the strategic posture of maximum risk absorption. A bastion host is a specially configured, highly hardened system explicitly designed to withstand attacks. By placing it beyond the outer perimeter, it acts as the true first line of defense. It scrubs, authenticates, and proxies traffic before that traffic is allowed to even touch the enterprise's primary perimeter firewall.

5. Why other options are weaker

  • A (Inside the DMZ): While commonly implemented in traditional networks, placing it inside the DMZ still allows untrusted traffic to pass through the outer firewall. For high-assurance governance (as tested in CCISO), pushing the risk completely outside the perimeter is preferred.
  • B (In-line with data center): This places a massive risk element too close to the core assets and creates a single point of failure that bottlenecks critical data center traffic.
  • D (Gatekeeper to honeynet): A bastion host provides legitimate, highly secure administrative access. A honeynet is a deceptive environment. Mixing these purposes violates the governance principle of separation of duties.
Mini Lesson: Architectural Governance & Risk Boundaries
Security architecture is not just about installing firewalls; it is the strategic definition of risk boundaries. A CISO must design networks assuming components will fail. The bastion host is designed to be a target. Therefore, governance dictates placing this "target" where its compromise will yield the lowest possible blast radius to the rest of the business—outside the trusted perimeter.
Executive Takeaway

"Design your architecture not to prevent failure, but to dictate exactly where and how the failure will be contained."

Ready for the next scenario?

Master executive-level cybersecurity decision-making.

Explore more CCISO simulations