Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

What is the primary purpose of configuring split tunneling on an SSL VPN?

⚠ Common exam trap

Test-takers frequently confuse split tunneling with full tunneling, mistakenly thinking split tunneling encrypts all traffic, when in fact it selectively routes only corporate traffic through the VPN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To allow the remote client to access both the corporate network and the Internet simultaneously without routing all traffic through the VPN

Split tunneling on an SSL VPN allows the remote client to have simultaneous access to the corporate network (via the encrypted VPN tunnel) and the public Internet (directly, without going through the VPN). This reduces bandwidth load on the VPN gateway and improves user experience by not routing non-corporate traffic through the encrypted tunnel. Option D correctly describes this behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To provide two-factor authentication for the VPN connection

    Why it's wrong here

    Two-factor authentication is a separate security control, typically implemented through FortiToken or other MFA solutions, that verifies the user's identity during the VPN authentication phase. Split tunneling, in contrast, is a routing configuration that determines which destination networks are sent through the encrypted tunnel and which are sent directly. Enabling split tunneling has no impact on the authentication method or the number of factors required to establish the VPN session.

  • ✗

    To encrypt all traffic from the remote client, including Internet traffic

    Why it's wrong here

    This description actually defines full tunneling, not split tunneling. In a full tunnel configuration, 100% of the client's traffic, including Internet-bound packets, is encapsulated and encrypted inside the VPN tunnel and then forwarded by the FortiGate to its final destination. Split tunneling, on the other hand, selectively routes only corporate-network traffic (e.g., to private IP ranges) through the tunnel, while allowing all other Internet traffic to be sent directly from the client's local network unencrypted to the ISP, thereby reducing VPN gateway load and latency.

  • ✗

    To enable the use of client certificates for authentication

    Why it's wrong here

    Client certificates are an authentication mechanism used during the IKE or SSL-VPN handshake to cryptographically verify the remote user's device identity, and they are configured via certificate authorities and peer IDs. Split tunneling is entirely a routing policy that controls traffic forwarding based on destination addresses, and it is unrelated to the authentication credentials or certificates used to establish the VPN. Even if client certificates are mandatory, split tunneling can be either enabled or disabled independently, as these two features operate on different layers of the VPN architecture.

  • ✓

    To allow the remote client to access both the corporate network and the Internet simultaneously without routing all traffic through the VPN

    Why this is correct

    Split tunneling is a VPN configuration that routes only traffic destined for the corporate network (e.g., private subnets or specific IP ranges) through the encrypted tunnel, while all other Internet-bound traffic exits directly from the client's local interface. This allows the remote user to simultaneously access corporate resources and general Internet services without forcing every packet through the VPN gateway, which reduces bandwidth consumption, lowers latency for unrelated web browsing, and prevents the VPN concentrator from becoming a bottleneck. The FortiGate implements this by adding specific routes for corporate CIDRs to be sent over the tunnel interface, leaving the default route on the physical adapter for direct Internet access.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.