CND Practice Question: Network Security Controls Protocols And Devices
A network administrator is configuring secure remote access for employees. The security policy mandates that the remote access solution must support multi-factor authentication (MFA) and encrypt all traffic from the client device. Which TWO technologies or protocols can meet these requirements? (Choose two)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL/TLS-based VPN (e.g., OpenVPN or AnyConnect) integrated with an identity provider for MFA
IPsec VPNs and SSL/TLS VPNs are both industry-standard remote access solutions that encrypt all traffic and integrate with AAA/MFA servers (like RADIUS/TACACS+ or SAML) to enforce multi-factor authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unencrypted Telnet management session over port 23
Why it's wrong here
Telnet provides zero encryption and does not support secure MFA remote access.
- ✗
Unauthenticated PPTP remote dial-up connection
Why it's wrong here
PPTP is obsolete, insecure, and lacks modern MFA or robust encryption.
- ✓
SSL/TLS-based VPN (e.g., OpenVPN or AnyConnect) integrated with an identity provider for MFA
Why this is correct
SSL/TLS VPNs encrypt traffic and integrate with modern MFA identity providers.
- ✗
Standard HTTP web browsing to internal unencrypted portals
Why it's wrong here
HTTP does not encrypt traffic and lacks remote access VPN capabilities.
- ✓
IPsec VPN client software configured with IKEv2 and certificate/MFA authentication
Why this is correct
IPsec VPNs provide robust encryption and support strong multi-factor authentication mechanisms.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.