FC0-U71 Security Practice Question
An IT technician is configuring a new employee's laptop. The employee will handle payroll data and must access the payroll application from home. The company requires that the connection be encrypted and that the employee's device prove its identity before access is granted. Which technology BEST meets these requirements?
⚠ Common exam trap
The trap here is accepting any encrypted connection, such as HTTPS, while overlooking that the requirement also demands the device itself prove its identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A VPN connection using IPsec or TLS with certificate-based authentication
The scenario requires two things: encryption of the connection and proof of the device's identity. A VPN with IPsec or TLS supplies the encrypted tunnel, while certificate-based authentication forces the laptop to present a valid digital certificate before the tunnel is established. Remote desktop, password-only web portals, and cloud sync either lack device authentication or fail to provide a private encrypted path to the payroll application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A secure web portal that requires a username and password
Why it's wrong here
HTTPS encrypts the browser session, but a username and password authenticate only the user, not the laptop. A stolen credential used from an unknown device would still be accepted, violating the device-identity requirement. Without a client certificate or similar device credential, this option cannot confirm that the approved laptop is the one connecting.
- ✗
File synchronization to a cloud storage folder shared with the payroll team
Why it's wrong here
Cloud file sync moves copies of payroll data to third-party storage, which may violate data-handling policies and expands the attack surface. It encrypts in transit to the provider but does not authenticate the device or provide a private tunnel into the corporate network. It also does not give the employee access to the payroll application itself, so it does not satisfy the scenario.
- ✗
Remote Desktop Protocol to an office workstation over the internet
Why it's wrong here
RDP provides a graphical session but does not encrypt the connection by default in older configurations, and it authenticates the user, not the device. Exposing RDP directly to the internet also invites brute-force and ransomware attacks. It fails the requirement that the device prove its identity and does not guarantee encryption without additional tunneling, so it is not the best fit.
- ✓
A VPN connection using IPsec or TLS with certificate-based authentication
Why this is correct
A VPN creates an encrypted tunnel between the laptop and the corporate network, protecting payroll data in transit. Certificate-based authentication requires the device to present a valid digital certificate, satisfying the requirement that the device prove its identity before access. Together, encryption and mutual authentication meet both stated conditions, unlike simpler remote-access methods.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.