ISC2 CC Network Security Practice Question
A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?
⚠ Common exam trap
The trap here is conflating site-to-site VPNs with remote access VPNs, even though only the latter is designed for individual clients initiating connections from outside the network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A remote access VPN terminating on a VPN concentrator
Remote employees need an encrypted path into the internal network that they initiate, so internal servers never connect back to them. A remote access VPN terminated on a concentrator provides exactly this client-initiated tunnel and can be scoped to specific internal resources. Site-to-site tunnels, reverse proxies, and NAC address different problems and do not meet both stated constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network access control (NAC) solution
Why it's wrong here
NAC enforces endpoint compliance and admission control before a device joins a network, often placing noncompliant devices in a quarantine VLAN. It does not create an encrypted tunnel for remote users or selectively forward traffic to internal trading applications. NAC is complementary to remote access but does not provide the confidentiality and reachability controls described in the scenario.
- ✓
A remote access VPN terminating on a VPN concentrator
Why this is correct
A remote access VPN lets individual clients establish an encrypted tunnel to a VPN concentrator, and split-tunnel or full-tunnel policies can restrict which internal resources are reachable. Because the client initiates the connection, internal application servers never need to initiate connections back to the client, satisfying the requirement. This design keeps internal applications off the public internet while giving employees authenticated access.
- ✗
A reverse proxy published in the DMZ
Why it's wrong here
A reverse proxy accepts inbound connections from the internet and forwards them to internal servers, which means the internal application servers do receive connections originating from outside clients. It also does not by itself provide an encrypted tunnel for arbitrary client traffic to multiple internal resources. While reverse proxies are useful for publishing web applications, they do not satisfy the requirement that internal servers never receive client-initiated connections.
- ✗
A site-to-site IPsec tunnel between two data centers
Why it's wrong here
A site-to-site IPsec tunnel connects entire networks, typically between gateways such as branch offices or data centers. It does not provide a per-user remote access mechanism for individual employees working from home. Deploying it for remote users would require a gateway at each user's location, which is impractical and does not match the scenario of remote employees needing selective access to internal applications.
Go deeper
Related to this question
Learn chapter
Wireless and Remote Access Security
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
Key term
Network Access Control
Network Access Control is a security solution that enforces policies to control which devices and users can connect to a network, ensuring only authorized and compliant endpoints gain access.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.