Your SOC receives an alert from a jump host in the DMZ indicating that an admin account successfully authenticated via SSH to a database server in the secure zone. The SIEM correlates this with a successful RDP session from the same source IP to the jump host five minutes prior. No other authentication events occurred on the jump host during this window. Why is this traffic pattern considered the expected behavior for this architecture?
Select an answer to reveal the explanation.
Short Explanation
Think of a jump host like the only revolving door into a high-security vault. You don't walk straight to the safe; you go through the door, and the door logs every swipe. If the SIEM shows you entered the door and then accessed the safe, that's the design working as intended. It’s not about blocking the access; it’s about making sure every single privileged action is captured in one place so you can actually audit it later.
Full Explanation
A jump host is a hardened administrative gateway placed at a trust boundary. In the expected pattern, the analyst first sees authentication to the bastion, then sees the bastion initiate the privileged session to the internal target. This creates a controlled access boundary because direct administrative traffic to sensitive servers is normally denied. The bastion's logs therefore provide a single audit trail for privileged sessions, showing who authenticated, what target was reached, and when the proxied connection occurred. A transparent network bridge would merely forward traffic and would not terminate or centrally log administrative sessions, so it would not create the same access boundary. A caching proxy is for application data optimization, not privileged remote administration, and would not explain an SSH or RDP administrative session. A standalone management console that runs scripts locally would not produce a successful proxied connection to the database server, so the correlated alert would not make sense. Exam caveat: distinguish administrative bastion access from application-layer proxies or load balancers. Operational check: confirm firewall policy permits SSH or RDP to internal servers only from the jump host management address.