ISC2 CC Network Security Practice Question
A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?
⚠ Common exam trap
Candidates often confuse encryption with data origin authentication and assuming that any encrypted tunnel proves who sent the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPsec in tunnel mode with confidentiality and data origin authentication enabled.
IPsec in tunnel mode with ESP confidentiality and authentication provides encryption for the images and cryptographically verifies the hospital as the origin. The remote clinic can validate the sender and detect any modification in transit. TLS with a certificate issued to the wrong party, shared SFTP credentials, and unencrypted GRE do not meet both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SFTP with a shared username and password for the radiology and clinic staff.
Why it's wrong here
SFTP encrypts the file transfer and can authenticate users, but a shared username and password does not provide strong data origin authentication for the hospital as an entity. It also weakens accountability because multiple people use the same credentials. The images would be protected in transit, but the clinic could not reliably verify that the hospital sent them.
- ✓
IPsec in tunnel mode with confidentiality and data origin authentication enabled.
Why this is correct
IPsec tunnel mode encapsulates the entire original IP packet and can apply ESP encryption for confidentiality plus an authentication mechanism that provides data origin authentication and integrity. This protects the images from being read or altered in transit and lets the remote clinic verify the hospital as the source. It matches both requirements in a single, standard site-to-site design.
- ✗
A site-to-site VPN using GRE without encryption or authentication.
Why it's wrong here
GRE alone provides encapsulation and can carry multicast or routing protocols, but it offers no confidentiality and no cryptographic authentication. Anyone who can capture the tunnel traffic can read the medical images, and there is no way for the clinic to verify the hospital as the source. This fails both the confidentiality and the data origin authentication requirements.
- ✗
TLS 1.3 with a server certificate issued to the remote clinic.
Why it's wrong here
TLS 1.3 can encrypt the transfer and authenticate the server, but the certificate is issued to the remote clinic, so the clinic is authenticated to the hospital rather than the hospital to the clinic. The requirement is for the clinic to verify the hospital as the sender. This reverses the trust direction and does not satisfy data origin authentication from the hospital's side.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
SFTP
SFTP (Secure File Transfer Protocol) is a network protocol that provides secure file transfer over SSH, encrypting both commands and data.
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.