Courseiva
Network SecurityhardMultiple ChoiceObjective-mapped

N10-009 Network Security Practice Question

A security engineer is configuring a site-to-site VPN between two branch offices. The requirement is to encrypt all traffic between the two networks using IPsec. Which IPsec mode should be used to encrypt the entire IP packet including the original header?

⚠ Common exam trap

The N10-009 exam often tests the distinction between Transport and Tunnel modes by asking which mode encrypts the entire packet, and candidates mistakenly choose Transport mode because they confuse 'encrypting the payload' with 'encrypting the entire packet', or they think AH provides encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tunnel mode

Tunnel mode is the correct choice because it encrypts the entire original IP packet, including the original header, and then encapsulates it within a new IP header. This is required for site-to-site VPNs where the original source and destination IP addresses must be hidden or protected, and the new header is used for routing between the two VPN gateways.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transport mode

    Why it's wrong here

    Transport mode encrypts only the payload of the original IP packet, leaving the original IP header unencrypted and visible. This means that the source and destination IP addresses of the communicating hosts are exposed to anyone monitoring the network traffic. While suitable for end-to-end host-to-host encryption, Transport mode is inappropriate for site-to-site VPNs, as it fails to conceal the network topology and internal addressing of the connected branches.

    When this WOULD be correct

    Transport mode would be correct when the VPN is used for end-to-end communication between two hosts (e.g., a client and server) and the requirement is to encrypt only the payload while preserving the original IP header for routing.

  • Tunnel mode

    Why this is correct

    Tunnel mode is the correct choice for site-to-site VPNs because it encapsulates the entire original IP packet, including both its header and payload, within a new, outer IP header. This comprehensive encapsulation ensures that the original source and destination IP addresses are hidden from intermediate networks, providing complete confidentiality and network-level anonymity. The new outer header then directs the packet to the VPN gateway at the remote site, making it ideal for connecting entire networks securely.

  • AH only

    Why it's wrong here

    The Authentication Header (AH) protocol within IPsec provides data integrity, data origin authentication, and anti-replay services by hashing the packet and adding an integrity check value. However, AH explicitly does not offer any encryption or confidentiality for the packet's contents. Therefore, using AH only would not encrypt the sensitive data traversing the VPN tunnel, failing to meet the fundamental requirement of a secure site-to-site VPN to protect information from eavesdropping.

    When this WOULD be correct

    When the requirement is only to authenticate and ensure integrity of IP packets without encryption, such as in a scenario where data confidentiality is not needed but protection against tampering is required.

  • ESP only

    Why it's wrong here

    Encapsulating Security Payload (ESP) is an IPsec protocol that provides confidentiality (encryption), data origin authentication, data integrity, and anti-replay services. However, simply selecting 'ESP only' does not specify the crucial encapsulation method required for a site-to-site VPN. ESP can operate in either transport or tunnel mode, and for a site-to-site connection, the entire original packet, including its header, must be encapsulated and encrypted, which is a function of tunnel mode, not solely the ESP protocol itself.

    When this WOULD be correct

    A question asking: 'Which IPsec protocol provides encryption but not authentication of the IP header?' would make ESP only correct, as AH provides authentication but not encryption.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

Tunnel modeCorrect answer

Why this is correct

Tunnel mode is the correct choice for site-to-site VPNs because it encapsulates the entire original IP packet, including both its header and payload, within a new, outer IP header. This comprehensive encapsulation ensures that the original source and destination IP addresses are hidden from intermediate networks, providing complete confidentiality and network-level anonymity. The new outer header then directs the packet to the VPN gateway at the remote site, making it ideal for connecting entire networks securely.

Transport modeWrong answer — click to see why

Why this is wrong here

Transport mode only encrypts the payload of the IP packet, leaving the original IP header intact, so it does not encrypt the entire packet including the header as required.

★ When this WOULD be the correct answer

Transport mode would be correct when the VPN is used for end-to-end communication between two hosts (e.g., a client and server) and the requirement is to encrypt only the payload while preserving the original IP header for routing.

Why candidates choose this

Candidates may confuse transport mode with tunnel mode, thinking both encrypt the entire packet, or they may not fully understand that transport mode excludes the header from encryption.

AH onlyWrong answer — click to see why

Why this is wrong here

AH only provides authentication and integrity, but does not encrypt the payload or the original header, failing to meet the requirement to encrypt all traffic.

★ When this WOULD be the correct answer

When the requirement is only to authenticate and ensure integrity of IP packets without encryption, such as in a scenario where data confidentiality is not needed but protection against tampering is required.

Why candidates choose this

Candidates may confuse AH with ESP, or think that AH provides encryption because it is part of IPsec, but AH only offers authentication, not encryption.

ESP onlyWrong answer — click to see why

Why this is wrong here

ESP only can be used in either transport or tunnel mode, but the question asks for the mode that encrypts the entire IP packet including the original header. ESP alone does not specify the mode; tunnel mode is required for full packet encryption.

★ When this WOULD be the correct answer

A question asking: 'Which IPsec protocol provides encryption but not authentication of the IP header?' would make ESP only correct, as AH provides authentication but not encryption.

Why candidates choose this

Candidates may confuse ESP with tunnel mode, thinking ESP inherently encrypts the entire packet, but ESP can operate in transport mode which only encrypts the payload.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.