200-901 Network Fundamentals Practice Question
A web application uses HTTPS to secure communications between client and server. What does HTTPS add on top of HTTP to provide encryption and authentication?
⚠ Common exam trap
200-901 often tests the layering confusion — candidates may pick IPsec or VPN because they associate 'encryption' with network-layer tunnels rather than the application-layer TLS that actually secures HTTPS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL/TLS
HTTPS is HTTP layered over SSL/TLS, which provides encryption (confidentiality), integrity, and server authentication via X.509 certificates. TLS negotiates a session key using asymmetric cryptography, then encrypts the HTTP payload with symmetric ciphers. This is what distinguishes HTTPS from plain HTTP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSH
Why it's wrong here
SSH is a separate secure remote-shell and tunnelling protocol; HTTPS instead layers TLS over HTTP for encryption and server authentication. It is tempting because both provide encrypted channels, and SSH would be correct for secure administrative access or port forwarding rather than securing web application traffic.
- ✗
IPsec
Why it's wrong here
IPsec operates at the IP layer to secure host-to-host or gateway-to-gateway traffic, so it cannot provide the application-layer TLS session that HTTPS uses for encryption and certificate-based server authentication. It is tempting because IPsec does encrypt packets, but it is the right choice for site-to-site VPNs, not public web traffic.
- ✓
SSL/TLS
Why this is correct
SSL/TLS operates between HTTP and TCP, encrypting the request and response payloads and authenticating the server via its certificate. Plain HTTP provides neither confidentiality nor identity verification, so layering TLS satisfies the encryption and authentication requirement.
- ✗
VPN
Why it's wrong here
A VPN tunnels traffic at the network layer between endpoints, so it cannot supply the per-connection TLS handshake that HTTPS relies on for encryption and server authentication. It is tempting because VPNs do encrypt traffic, but they are the right choice for securing remote access to a private network, not for a public web application.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.