easyMultiple Select
CCNP Practice Question: Which three statements about SSL VPNs are true?…
Which three statements about SSL VPNs are true? (Choose three.)
⚠ Common exam trap
The trap here is conflating SSL VPN authentication with IPsec's pre-shared key model, and assuming SSL VPNs are locked to TCP 443 when they actually support multiple ports and DTLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL VPNs use the TLS protocol to encrypt traffic between client and server.
Option A is correct because SSL VPNs fundamentally rely on the TLS (Transport Layer Security) protocol to provide encryption, integrity, and authentication for the tunnel between the client and the VPN gateway. Option C is correct because clientless SSL VPN mode requires only a standard web browser and typically provides access to web-based applications through a portal, without installing a dedicated client. Option E is correct because SSL VPN clients can support port forwarding, which redirects traffic from specific local TCP ports to resources behind the VPN gateway, enabling access to non-web applications. Option B is not correct because SSL VPNs commonly authenticate users with certificates, usernames/passwords, or multi-factor methods; a pre-shared key is characteristic of IPsec VPNs, not a general SSL VPN requirement. Option D is not correct because although SSL VPNs commonly use TCP port 443, they are not limited to it and can be configured on other ports or use DTLS/UDP for performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSL VPNs use the TLS protocol to encrypt traffic between client and server.
Why this is correct
SSL VPNs operate over TLS, the successor to SSL, encrypting the session between client and server at the transport layer. This satisfies the stem's requirement for a true statement about SSL VPNs, since TLS provides the cryptographic tunnel without requiring IPsec or dedicated client software in clientless deployments.
- ✗
SSL VPNs require a pre-shared key for authentication.
Why it's wrong here
SSL VPNs authenticate with certificates, credentials or SAML through TLS; a pre-shared key belongs to IPsec IKE peer authentication. It is tempting because PSKs are common in site-to-site IPsec VPNs, which would make the statement correct there, but not for clientless or client-based SSL VPN access.
- ✓
Clientless SSL VPN access allows users to access web applications using only a browser.
Why this is correct
Clientless SSL VPN access requires only a browser, presenting internal web applications through a portal without installing client software. This browser-only access model satisfies the stem's requirement for a true statement about SSL VPN operation.
- ✗
SSL VPNs can only operate over TCP port 443.
Why it's wrong here
SSL VPNs can run over any TCP or UDP port, and DTLS uses UDP for performance; port 443 is merely conventional. It is tempting because HTTPS-based clientless access typically uses 443 to traverse firewalls, which would make the statement true only for that specific deployment style.
- ✓
SSL VPNs support port forwarding for non-web applications.
Why this is correct
SSL VPNs tunnel specific TCP ports through the browser plug-in or client, letting users reach non-web applications such as RDP or SMTP without exposing them publicly. This satisfies the requirement to access internal services that do not speak HTTP over the same encrypted session.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.