N10-009 Network Security Practice Question
A security engineer is configuring a site-to-site VPN between two branch offices. The requirement is to encrypt all traffic between the two networks using IPsec. Which IPsec mode should be used to encrypt the entire IP packet including the original header?
⚠ Common exam trap
The N10-009 exam often tests the distinction between Transport and Tunnel modes by asking which mode encrypts the entire packet, and candidates mistakenly choose Transport mode because they confuse 'encrypting the payload' with 'encrypting the entire packet', or they think AH provides encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tunnel mode
Tunnel mode is the correct choice because it encrypts the entire original IP packet, including the original header, and then encapsulates it within a new IP header. This is required for site-to-site VPNs where the original source and destination IP addresses must be hidden or protected, and the new header is used for routing between the two VPN gateways.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transport mode
Why it's wrong here
Transport mode encrypts only the payload of the original IP packet, leaving the original IP header unencrypted and visible. This means that the source and destination IP addresses of the communicating hosts are exposed to anyone monitoring the network traffic. While suitable for end-to-end host-to-host encryption, Transport mode is inappropriate for site-to-site VPNs, as it fails to conceal the network topology and internal addressing of the connected branches.
When this WOULD be correct
Transport mode would be correct when the VPN is used for end-to-end communication between two hosts (e.g., a client and server) and the requirement is to encrypt only the payload while preserving the original IP header for routing.
- ✓
Tunnel mode
Why this is correct
Tunnel mode is the correct choice for site-to-site VPNs because it encapsulates the entire original IP packet, including both its header and payload, within a new, outer IP header. This comprehensive encapsulation ensures that the original source and destination IP addresses are hidden from intermediate networks, providing complete confidentiality and network-level anonymity. The new outer header then directs the packet to the VPN gateway at the remote site, making it ideal for connecting entire networks securely.
- ✗
AH only
Why it's wrong here
The Authentication Header (AH) protocol within IPsec provides data integrity, data origin authentication, and anti-replay services by hashing the packet and adding an integrity check value. However, AH explicitly does not offer any encryption or confidentiality for the packet's contents. Therefore, using AH only would not encrypt the sensitive data traversing the VPN tunnel, failing to meet the fundamental requirement of a secure site-to-site VPN to protect information from eavesdropping.
When this WOULD be correct
When the requirement is only to authenticate and ensure integrity of IP packets without encryption, such as in a scenario where data confidentiality is not needed but protection against tampering is required.
- ✗
ESP only
Why it's wrong here
Encapsulating Security Payload (ESP) is an IPsec protocol that provides confidentiality (encryption), data origin authentication, data integrity, and anti-replay services. However, simply selecting 'ESP only' does not specify the crucial encapsulation method required for a site-to-site VPN. ESP can operate in either transport or tunnel mode, and for a site-to-site connection, the entire original packet, including its header, must be encapsulated and encrypted, which is a function of tunnel mode, not solely the ESP protocol itself.
When this WOULD be correct
A question asking: 'Which IPsec protocol provides encryption but not authentication of the IP header?' would make ESP only correct, as AH provides authentication but not encryption.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Tunnel modeCorrect answer▾
Why this is correct
Tunnel mode is the correct choice for site-to-site VPNs because it encapsulates the entire original IP packet, including both its header and payload, within a new, outer IP header. This comprehensive encapsulation ensures that the original source and destination IP addresses are hidden from intermediate networks, providing complete confidentiality and network-level anonymity. The new outer header then directs the packet to the VPN gateway at the remote site, making it ideal for connecting entire networks securely.
✗Transport modeWrong answer — click to see why▾
Why this is wrong here
Transport mode only encrypts the payload of the IP packet, leaving the original IP header intact, so it does not encrypt the entire packet including the header as required.
★ When this WOULD be the correct answer
Transport mode would be correct when the VPN is used for end-to-end communication between two hosts (e.g., a client and server) and the requirement is to encrypt only the payload while preserving the original IP header for routing.
Why candidates choose this
Candidates may confuse transport mode with tunnel mode, thinking both encrypt the entire packet, or they may not fully understand that transport mode excludes the header from encryption.
✗AH onlyWrong answer — click to see why▾
Why this is wrong here
AH only provides authentication and integrity, but does not encrypt the payload or the original header, failing to meet the requirement to encrypt all traffic.
★ When this WOULD be the correct answer
When the requirement is only to authenticate and ensure integrity of IP packets without encryption, such as in a scenario where data confidentiality is not needed but protection against tampering is required.
Why candidates choose this
Candidates may confuse AH with ESP, or think that AH provides encryption because it is part of IPsec, but AH only offers authentication, not encryption.
✗ESP onlyWrong answer — click to see why▾
Why this is wrong here
ESP only can be used in either transport or tunnel mode, but the question asks for the mode that encrypts the entire IP packet including the original header. ESP alone does not specify the mode; tunnel mode is required for full packet encryption.
★ When this WOULD be the correct answer
A question asking: 'Which IPsec protocol provides encryption but not authentication of the IP header?' would make ESP only correct, as AH provides authentication but not encryption.
Why candidates choose this
Candidates may confuse ESP with tunnel mode, thinking ESP inherently encrypts the entire packet, but ESP can operate in transport mode which only encrypts the payload.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
VPNs and Remote Access
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
IPsec
IPsec is a suite of protocols used to secure Internet Protocol (IP) communications by encrypting and authenticating each IP packet in a data stream.
About these practice questions
This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.