Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?

⚠ Common exam trap

The trap here is selecting a transport-layer protocol like TLS 1.3 because it also supports perfect forward secrecy, without considering the network-layer and hardware acceleration requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPsec with IKEv2

IPsec with IKEv2 operates at the network layer, supports perfect forward secrecy through Diffie-Hellman, and is widely implemented in hardware for high throughput. The other protocols either operate at higher layers or are not typically hardware-accelerated for site-to-site network-layer encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IPsec with IKEv2

    Why this is correct

    IPsec operates at the network layer and can be implemented in hardware for high throughput. IKEv2 supports perfect forward secrecy through Diffie-Hellman key exchange, ensuring that compromise of long-term keys does not compromise past session keys. This combination provides confidentiality and high availability for data in transit between data centers.

  • ✗

    Secure Shell (SSH) tunneling

    Why it's wrong here

    SSH tunneling operates at the application layer and is not designed for high-throughput network-layer encryption. While it supports perfect forward secrecy, it is not typically hardware-accelerated and is more suited for remote administration or individual port forwarding rather than site-to-site data center connectivity.

  • ✗

    Datagram Transport Layer Security (DTLS)

    Why it's wrong here

    DTLS is based on TLS and operates at the transport layer, providing security for datagram protocols such as UDP. It supports perfect forward secrecy, but it is not a network-layer protocol and is not commonly implemented in hardware for high-throughput site-to-site VPNs. It is better suited for real-time applications like VoIP or gaming.

  • ✗

    Transport Layer Security (TLS) 1.3

    Why it's wrong here

    TLS 1.3 operates at the transport layer and supports perfect forward secrecy, but it is not typically implemented in hardware for network-layer throughput. It is designed for application-layer protocols and requires termination at endpoints or load balancers, which may not meet the requirement for a network-layer solution with hardware acceleration.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.