NSE4 Authentication and VPN Practice Question
What is the primary purpose of configuring split tunneling on an SSL VPN?
⚠ Common exam trap
Test-takers frequently confuse split tunneling with full tunneling, mistakenly thinking split tunneling encrypts all traffic, when in fact it selectively routes only corporate traffic through the VPN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow the remote client to access both the corporate network and the Internet simultaneously without routing all traffic through the VPN
Split tunneling on an SSL VPN allows the remote client to have simultaneous access to the corporate network (via the encrypted VPN tunnel) and the public Internet (directly, without going through the VPN). This reduces bandwidth load on the VPN gateway and improves user experience by not routing non-corporate traffic through the encrypted tunnel. Option D correctly describes this behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To provide two-factor authentication for the VPN connection
Why it's wrong here
Two-factor authentication is a separate security control, typically implemented through FortiToken or other MFA solutions, that verifies the user's identity during the VPN authentication phase. Split tunneling, in contrast, is a routing configuration that determines which destination networks are sent through the encrypted tunnel and which are sent directly. Enabling split tunneling has no impact on the authentication method or the number of factors required to establish the VPN session.
- ✗
To encrypt all traffic from the remote client, including Internet traffic
Why it's wrong here
This description actually defines full tunneling, not split tunneling. In a full tunnel configuration, 100% of the client's traffic, including Internet-bound packets, is encapsulated and encrypted inside the VPN tunnel and then forwarded by the FortiGate to its final destination. Split tunneling, on the other hand, selectively routes only corporate-network traffic (e.g., to private IP ranges) through the tunnel, while allowing all other Internet traffic to be sent directly from the client's local network unencrypted to the ISP, thereby reducing VPN gateway load and latency.
- ✗
To enable the use of client certificates for authentication
Why it's wrong here
Client certificates are an authentication mechanism used during the IKE or SSL-VPN handshake to cryptographically verify the remote user's device identity, and they are configured via certificate authorities and peer IDs. Split tunneling is entirely a routing policy that controls traffic forwarding based on destination addresses, and it is unrelated to the authentication credentials or certificates used to establish the VPN. Even if client certificates are mandatory, split tunneling can be either enabled or disabled independently, as these two features operate on different layers of the VPN architecture.
- ✓
To allow the remote client to access both the corporate network and the Internet simultaneously without routing all traffic through the VPN
Why this is correct
Split tunneling is a VPN configuration that routes only traffic destined for the corporate network (e.g., private subnets or specific IP ranges) through the encrypted tunnel, while all other Internet-bound traffic exits directly from the client's local interface. This allows the remote user to simultaneously access corporate resources and general Internet services without forcing every packet through the VPN gateway, which reduces bandwidth consumption, lowers latency for unrelated web browsing, and prevents the VPN concentrator from becoming a bottleneck. The FortiGate implements this by adding specific routes for corporate CIDRs to be sent over the tunnel interface, leaving the default route on the physical adapter for direct Internet access.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.