Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

An IT technician is configuring a new employee's laptop. The employee will handle payroll data and must access the payroll application from home. The company requires that the connection be encrypted and that the employee's device prove its identity before access is granted. Which technology BEST meets these requirements?

⚠ Common exam trap

The trap here is accepting any encrypted connection, such as HTTPS, while overlooking that the requirement also demands the device itself prove its identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A VPN connection using IPsec or TLS with certificate-based authentication

The scenario requires two things: encryption of the connection and proof of the device's identity. A VPN with IPsec or TLS supplies the encrypted tunnel, while certificate-based authentication forces the laptop to present a valid digital certificate before the tunnel is established. Remote desktop, password-only web portals, and cloud sync either lack device authentication or fail to provide a private encrypted path to the payroll application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A secure web portal that requires a username and password

    Why it's wrong here

    HTTPS encrypts the browser session, but a username and password authenticate only the user, not the laptop. A stolen credential used from an unknown device would still be accepted, violating the device-identity requirement. Without a client certificate or similar device credential, this option cannot confirm that the approved laptop is the one connecting.

  • ✗

    File synchronization to a cloud storage folder shared with the payroll team

    Why it's wrong here

    Cloud file sync moves copies of payroll data to third-party storage, which may violate data-handling policies and expands the attack surface. It encrypts in transit to the provider but does not authenticate the device or provide a private tunnel into the corporate network. It also does not give the employee access to the payroll application itself, so it does not satisfy the scenario.

  • ✗

    Remote Desktop Protocol to an office workstation over the internet

    Why it's wrong here

    RDP provides a graphical session but does not encrypt the connection by default in older configurations, and it authenticates the user, not the device. Exposing RDP directly to the internet also invites brute-force and ransomware attacks. It fails the requirement that the device prove its identity and does not guarantee encryption without additional tunneling, so it is not the best fit.

  • ✓

    A VPN connection using IPsec or TLS with certificate-based authentication

    Why this is correct

    A VPN creates an encrypted tunnel between the laptop and the corporate network, protecting payroll data in transit. Certificate-based authentication requires the device to present a valid digital certificate, satisfying the requirement that the device prove its identity before access. Together, encryption and mutual authentication meet both stated conditions, unlike simpler remote-access methods.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.