GSEC Networking and Protocols Practice Question
A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?
⚠ Common exam trap
The trap here is equating strong authentication with client certificates, when server-certificate validation plus multi-factor authentication can meet the requirement without provisioning anything on the personal device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a TLS-based VPN portal with multi-factor authentication, server certificates, and HSTS enforced.
The design must authenticate the server, resist credential theft, resist man-in-the-middle, and avoid client certificates on personal devices. A TLS-based VPN portal with MFA and server certificates meets all of these: the client validates the server certificate, MFA blocks stolen-password reuse, and HSTS prevents downgrade attacks. The other options either require client certificates, rely on weak shared secrets, or use reusable basic credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a TLS-based VPN portal with multi-factor authentication, server certificates, and HSTS enforced.
Why this is correct
A TLS-based portal authenticates the server with a certificate the client validates, and multi-factor authentication protects against stolen passwords. HSTS forces browsers to use HTTPS and prevents downgrade or SSL-stripping attacks. Because the client only needs to trust the server certificate and complete MFA, no client certificate is required on the personal device, satisfying all stated constraints.
- ✗
Publish the internal application through a reverse proxy that uses basic authentication over HTTPS.
Why it's wrong here
Basic authentication transmits reusable credentials with each request, and although HTTPS protects them in transit, the credentials remain vulnerable to phishing and replay if captured elsewhere. There is no second factor and no strong server identity validation described. This does not adequately protect against credential theft or MITM, so it fails the security requirements of the scenario.
- ✗
Deploy an IPsec VPN that requires a client certificate issued to each device.
Why it's wrong here
Requiring a client certificate provides strong mutual authentication, but it directly violates the constraint that no client certificate be installed on personal devices. Provisioning and managing certificates on unmanaged devices is also operationally impractical. Although secure, this approach does not meet the stated requirement, so it cannot be the correct design.
- ✗
Deploy an IPsec VPN with pre-shared keys distributed to each employee's device.
Why it's wrong here
Pre-shared keys are shared secrets that are difficult to distribute securely and do not scale; if one device is compromised, the key must be changed for everyone. They also do not provide strong per-user authentication or resistance to phishing. The scenario requires protection against credential theft and MITM without client certificates, and pre-shared keys introduce operational and security weaknesses that fail that requirement.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.