Courseiva
Network Security Controls Protocols And DevicesmediumMultiple SelectObjective-mapped

CND Practice Question: Network Security Controls Protocols And Devices

A network administrator is configuring secure remote access for employees. The security policy mandates that the remote access solution must support multi-factor authentication (MFA) and encrypt all traffic from the client device. Which TWO technologies or protocols can meet these requirements? (Choose two)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SSL/TLS-based VPN (e.g., OpenVPN or AnyConnect) integrated with an identity provider for MFA

IPsec VPNs and SSL/TLS VPNs are both industry-standard remote access solutions that encrypt all traffic and integrate with AAA/MFA servers (like RADIUS/TACACS+ or SAML) to enforce multi-factor authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Unencrypted Telnet management session over port 23

    Why it's wrong here

    Telnet provides zero encryption and does not support secure MFA remote access.

  • Unauthenticated PPTP remote dial-up connection

    Why it's wrong here

    PPTP is obsolete, insecure, and lacks modern MFA or robust encryption.

  • SSL/TLS-based VPN (e.g., OpenVPN or AnyConnect) integrated with an identity provider for MFA

    Why this is correct

    SSL/TLS VPNs encrypt traffic and integrate with modern MFA identity providers.

  • Standard HTTP web browsing to internal unencrypted portals

    Why it's wrong here

    HTTP does not encrypt traffic and lacks remote access VPN capabilities.

  • IPsec VPN client software configured with IKEv2 and certificate/MFA authentication

    Why this is correct

    IPsec VPNs provide robust encryption and support strong multi-factor authentication mechanisms.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.