CAS-004 Security Architecture Practice Question
A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?
⚠ Common exam trap
The trap here is selecting a transport-layer protocol like TLS 1.3 because it also supports perfect forward secrecy, without considering the network-layer and hardware acceleration requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPsec with IKEv2
IPsec with IKEv2 operates at the network layer, supports perfect forward secrecy through Diffie-Hellman, and is widely implemented in hardware for high throughput. The other protocols either operate at higher layers or are not typically hardware-accelerated for site-to-site network-layer encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IPsec with IKEv2
Why this is correct
IPsec operates at the network layer and can be implemented in hardware for high throughput. IKEv2 supports perfect forward secrecy through Diffie-Hellman key exchange, ensuring that compromise of long-term keys does not compromise past session keys. This combination provides confidentiality and high availability for data in transit between data centers.
- ✗
Secure Shell (SSH) tunneling
Why it's wrong here
SSH tunneling operates at the application layer and is not designed for high-throughput network-layer encryption. While it supports perfect forward secrecy, it is not typically hardware-accelerated and is more suited for remote administration or individual port forwarding rather than site-to-site data center connectivity.
- ✗
Datagram Transport Layer Security (DTLS)
Why it's wrong here
DTLS is based on TLS and operates at the transport layer, providing security for datagram protocols such as UDP. It supports perfect forward secrecy, but it is not a network-layer protocol and is not commonly implemented in hardware for high-throughput site-to-site VPNs. It is better suited for real-time applications like VoIP or gaming.
- ✗
Transport Layer Security (TLS) 1.3
Why it's wrong here
TLS 1.3 operates at the transport layer and supports perfect forward secrecy, but it is not typically implemented in hardware for network-layer throughput. It is designed for application-layer protocols and requires termination at endpoints or load balancers, which may not meet the requirement for a network-layer solution with hardware acceleration.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.