220-1102 Security Practice Question
A security audit reveals that a legacy application running on a Windows 10 workstation transmits sensitive data over an unencrypted protocol. The application is critical for business operations and cannot be updated or replaced. The workstation is located in a secured server room with restricted physical access. Which of the following would BEST mitigate the risk of data interception for this legacy application?
⚠ Common exam trap
Test-takers frequently choose a VPN solution (Option B) thinking it always encrypts all traffic, but they overlook that VPNs may not cover all traffic types or destinations, and the question specifies the workstation is in a secured server room, making IPsec a more direct and always-on encryption method without relying on a separate VPN server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement an IPsec policy on the workstation to encrypt all network traffic.
IPsec can be configured on the Windows 10 workstation to encrypt all outbound and inbound network traffic at the IP layer, regardless of the application protocol. This provides transparent encryption for the legacy application's unencrypted data without requiring any changes to the application itself, which is critical since the application cannot be updated or replaced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement an IPsec policy on the workstation to encrypt all network traffic.
Why this is correct
IPsec operates at the network layer (Layer 3), so it encrypts all IP-based traffic from the workstation, regardless of the application protocol used by the legacy software. Because it is enforced at the OS or policy level, it can be applied without modifying the application, and it protects against data interception on the LAN. A persistent IPsec policy via Group Policy or local security policy ensures encryption is always active.
- ✗
Install a VPN client on the workstation and connect to a corporate VPN server.
Why it's wrong here
A VPN only encrypts traffic that goes through the VPN tunnel. If the legacy application uses a non-VPN route or the VPN disconnects, data could be exposed. Also, it may not encrypt local network traffic.
- ✗
Change the application configuration to use HTTPS for communication.
Why it's wrong here
Changing the application configuration to use HTTPS is not viable because the scenario explicitly states the legacy application cannot be updated or replaced, and it likely doesn't support TLS. Even if it did, HTTPS only protects the traffic for that specific application while leaving all other unencrypted traffic exposed. The correct approach is to implement network-layer encryption like IPsec, which is application-agnostic.
- ✗
Place the workstation on an isolated VLAN that has no access to external networks.
Why it's wrong here
VLAN isolation can reduce the attack surface, but it does not encrypt the data still transmitted over the network. Data on the isolated VLAN could still be intercepted by an attacker with access to that VLAN.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Audit Logging and Review
Key term
Internet Protocol Security
Internet Protocol Security (IPsec) is a suite of protocols that encrypts and authenticates data packets sent over IP networks to ensure private and secure communication.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.