220-1101 Networking Practice Question
A network technician is tasked with providing secure remote access for employees who work from home. The solution must encrypt all traffic between the remote devices and the corporate network and must allow the remote devices to access internal resources (e.g., file servers, intranet) as if they were directly connected to the office LAN. Which of the following technologies should the technician implement?
⚠ Common exam trap
Candidates often confuse VLANs (Layer 2 segmentation) with VPNs (encrypted remote access), or they think port forwarding alone provides secure remote access, but it lacks encryption and full LAN integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN
A VPN (Virtual Private Network) is the correct technology because it creates an encrypted tunnel (using protocols like IPSec, OpenVPN, or WireGuard) between the remote device and the corporate network. This ensures all traffic is encrypted in transit and the remote device receives a virtual IP on the corporate LAN, allowing seamless access to internal resources such as file servers and intranets as if directly connected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPN
Why this is correct
A VPN builds an encrypted tunnel between the remote device and the corporate gateway, so all traffic is protected in transit and the device receives an internal address, reaching file servers and intranet hosts exactly as if on the office LAN.
- ✗
VLAN
Why it's wrong here
A VLAN logically segments devices within one Layer 2 broadcast domain; it provides no encryption and cannot extend LAN membership across the internet to a home device. It is tempting because VLANs isolate and group internal traffic, which would be correct for departmental separation inside a site, not remote access.
- ✗
DMZ
Why it's wrong here
A DMZ is a segmented subnet exposing public-facing services to untrusted networks; it neither encrypts remote traffic nor grants LAN-equivalent access to internal file servers. It is tempting because DMZs harden perimeter exposure, which would be correct for hosting externally reachable servers, not for remote worker connectivity.
- ✗
Port forwarding
Why it's wrong here
Port forwarding merely maps an external port to an internal host, exposing that service without encrypting traffic or granting full LAN-equivalent access. It is tempting because it enables inbound reachability to internal resources, which would be correct for publishing a single service, not for secure remote workforce access.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.