Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security audit reveals that a legacy application running on a Windows 10 workstation transmits sensitive data over an unencrypted protocol. The application is critical for business operations and cannot be updated or replaced. The workstation is located in a secured server room with restricted physical access. Which of the following would BEST mitigate the risk of data interception for this legacy application?

⚠ Common exam trap

Test-takers frequently choose a VPN solution (Option B) thinking it always encrypts all traffic, but they overlook that VPNs may not cover all traffic types or destinations, and the question specifies the workstation is in a secured server room, making IPsec a more direct and always-on encryption method without relying on a separate VPN server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement an IPsec policy on the workstation to encrypt all network traffic.

IPsec can be configured on the Windows 10 workstation to encrypt all outbound and inbound network traffic at the IP layer, regardless of the application protocol. This provides transparent encryption for the legacy application's unencrypted data without requiring any changes to the application itself, which is critical since the application cannot be updated or replaced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement an IPsec policy on the workstation to encrypt all network traffic.

    Why this is correct

    IPsec operates at the network layer (Layer 3), so it encrypts all IP-based traffic from the workstation, regardless of the application protocol used by the legacy software. Because it is enforced at the OS or policy level, it can be applied without modifying the application, and it protects against data interception on the LAN. A persistent IPsec policy via Group Policy or local security policy ensures encryption is always active.

  • ✗

    Install a VPN client on the workstation and connect to a corporate VPN server.

    Why it's wrong here

    A VPN only encrypts traffic that goes through the VPN tunnel. If the legacy application uses a non-VPN route or the VPN disconnects, data could be exposed. Also, it may not encrypt local network traffic.

  • ✗

    Change the application configuration to use HTTPS for communication.

    Why it's wrong here

    Changing the application configuration to use HTTPS is not viable because the scenario explicitly states the legacy application cannot be updated or replaced, and it likely doesn't support TLS. Even if it did, HTTPS only protects the traffic for that specific application while leaving all other unencrypted traffic exposed. The correct approach is to implement network-layer encryption like IPsec, which is application-agnostic.

  • ✗

    Place the workstation on an isolated VLAN that has no access to external networks.

    Why it's wrong here

    VLAN isolation can reduce the attack surface, but it does not encrypt the data still transmitted over the network. Data on the isolated VLAN could still be intercepted by an attacker with access to that VLAN.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.