Courseiva
Network Security →mediumMultiple Choice

ISC2 CC Network Security Practice Question

A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?

⚠ Common exam trap

The trap here is treating any technology that hides or forwards traffic, such as a proxy, as equivalent to an encrypted authenticated remote-access tunnel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A virtual private network (VPN)

The policy requires an encrypted tunnel over the public internet plus user authentication for internal application access. A VPN provides exactly that by encapsulating traffic and terminating at the corporate edge after verifying credentials. DMZs isolate public services, VLANs segment local networks, and proxies forward specific requests, but none deliver the encrypted authenticated remote-access tunnel described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A demilitarized zone (DMZ)

    Why it's wrong here

    A DMZ is a network segment that hosts public-facing services while isolating them from the internal network. It does not create encrypted tunnels for remote users or authenticate them for internal application access. Deploying a DMZ would not satisfy the remote-access requirement and would not encrypt employee traffic over the internet.

  • ✗

    A proxy server

    Why it's wrong here

    A proxy server forwards client requests, often for web filtering or caching, and can hide a client's source address for those requests. However, it does not create a general encrypted tunnel for all traffic or authenticate users for broad internal application access. It fails to meet the requirement that traffic be encrypted and appear to originate from the corporate network.

  • ✓

    A virtual private network (VPN)

    Why this is correct

    A VPN establishes an encrypted tunnel between the remote employee and the corporate network, protecting data in transit over the public internet. It also authenticates users before allowing access to internal applications, which matches the policy. This makes it the appropriate technology for secure remote access in this scenario.

  • ✗

    A virtual local area network (VLAN)

    Why it's wrong here

    A VLAN logically segments a local network at Layer 2, grouping devices regardless of physical location. It does not encrypt traffic over the public internet or authenticate remote users. While VLANs can improve internal segmentation, they cannot provide the encrypted remote tunnel and user authentication that the policy demands.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.