mediumMultiple Choice
220-1202 Practice Question: A technician is configuring a new firewall for a…
A technician is configuring a new firewall for a small office. They need to allow remote employees to securely access the internal network. Which technology should be enabled on the firewall?
⚠ Common exam trap
Many exam-takers confuse 'VPN passthrough' (which only forwards existing VPN traffic) with 'VPN server' (which terminates and creates VPN connections), leading them to select option B when the question explicitly asks for enabling secure remote access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN server
A VPN server on the firewall enables secure remote access by encrypting traffic between remote employees and the internal network, typically using protocols like IPsec or SSL/TLS. This provides authenticated, encrypted tunnels that protect data in transit, which is the standard solution for secure remote connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Port forwarding
Why it's wrong here
Port forwarding merely maps an external port to one internal host, giving no user authentication or tunnel encryption, so any exposed service is reachable directly. It is tempting for publishing a single internal server, such as RDP or a web host, to the internet, which is a different requirement from secure remote-user access.
- ✗
VPN passthrough
Why it's wrong here
VPN passthrough only permits already-encrypted VPN protocols to traverse the firewall; it terminates nothing and authenticates no remote user. It is tempting because it mentions VPN, but it suits a site where an internal VPN server sits behind the firewall and clients connect to that server, not the firewall itself.
- ✓
VPN server
Why this is correct
A VPN server terminates encrypted tunnels from remote employees, giving them secure access to internal resources over the public internet. This directly satisfies the requirement for secure remote access, unlike packet filtering or NAT, which do not provide encrypted tunnelling.
- ✗
DMZ
Why it's wrong here
A DMZ hosts publicly reachable services on a segmented subnet; it does not authenticate remote users nor encrypt their traffic into the internal LAN. It is tempting because DMZs commonly sit on firewalls, but they suit exposing web or mail servers to the internet, not granting remote employees secure internal access.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.