Courseiva
easyMultiple Choice

CV0-004 Practice Question: Protect data in transit between its on-premises…

A company wants to protect data in transit between its on-premises data center and a public cloud environment. Which technology should be used to create a secure encrypted tunnel over the internet?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN

A VPN (Virtual Private Network) creates an encrypted tunnel over the internet. TLS is used for web traffic, not for site-to-site tunnels. SSH is for remote admin, and a firewall is for filtering, not encrypting tunnels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSH

    Why it's wrong here

    SSH provides encrypted remote shell access to a single host, not a site-to-site tunnel carrying arbitrary traffic between networks. It is tempting because SSH tunnelling can forward ports, but a data-centre-to-cloud link needs IPsec or TLS-based VPN gateways that encrypt all routed traffic.

  • ✗

    Firewall

    Why it's wrong here

    A firewall filters traffic by port, protocol and address; it cannot encapsulate packets into an encrypted tunnel, so data crosses the internet in cleartext. It is tempting because firewalls do secure the network perimeter and are correct when the requirement is to permit or deny specific inbound and outbound flows, not to protect data in transit.

  • ✗

    TLS

    Why it's wrong here

    TLS encrypts individual application sessions such as HTTPS, but it does not build a site-to-site tunnel carrying all on-premises-to-cloud traffic. It is tempting because TLS genuinely protects data in transit, and it would be the right choice for securing a single web application's client connections rather than a data-centre interconnect.

  • ✓

    VPN

    Why this is correct

    A VPN establishes an encrypted tunnel between the on-premises gateway and the cloud endpoint across the public internet, encapsulating traffic with protocols such as IPsec or TLS. This satisfies the requirement to protect data in transit between the data centre and public cloud.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.