Courseiva
mediumMultiple Choice

220-1202 Practice Question: A technician is configuring a new firewall for a…

A technician is configuring a new firewall for a small office. They need to allow remote employees to securely access the internal network. Which technology should be enabled on the firewall?

⚠ Common exam trap

Many exam-takers confuse 'VPN passthrough' (which only forwards existing VPN traffic) with 'VPN server' (which terminates and creates VPN connections), leading them to select option B when the question explicitly asks for enabling secure remote access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN server

A VPN server on the firewall enables secure remote access by encrypting traffic between remote employees and the internal network, typically using protocols like IPsec or SSL/TLS. This provides authenticated, encrypted tunnels that protect data in transit, which is the standard solution for secure remote connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Port forwarding

    Why it's wrong here

    Port forwarding merely maps an external port to one internal host, giving no user authentication or tunnel encryption, so any exposed service is reachable directly. It is tempting for publishing a single internal server, such as RDP or a web host, to the internet, which is a different requirement from secure remote-user access.

  • ✗

    VPN passthrough

    Why it's wrong here

    VPN passthrough only permits already-encrypted VPN protocols to traverse the firewall; it terminates nothing and authenticates no remote user. It is tempting because it mentions VPN, but it suits a site where an internal VPN server sits behind the firewall and clients connect to that server, not the firewall itself.

  • ✓

    VPN server

    Why this is correct

    A VPN server terminates encrypted tunnels from remote employees, giving them secure access to internal resources over the public internet. This directly satisfies the requirement for secure remote access, unlike packet filtering or NAT, which do not provide encrypted tunnelling.

  • ✗

    DMZ

    Why it's wrong here

    A DMZ hosts publicly reachable services on a segmented subnet; it does not authenticate remote users nor encrypt their traffic into the internal LAN. It is tempting because DMZs commonly sit on firewalls, but they suit exposing web or mail servers to the internet, not granting remote employees secure internal access.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.