Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?

⚠ Common exam trap

Watch out — candidates often confuse endpoint security controls, such as host intrusion prevention, with the transport security and authentication that a remote access VPN actually provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A remote access VPN using TLS or IPsec.

A remote access VPN is designed exactly for this need: it authenticates the user at a central gateway and encrypts traffic between the remote device and the corporate network. The other choices address endpoint protection, local network admission control, or web application defense, none of which establish an authenticated, encrypted path to internal file shares for off-site workers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A web application firewall protecting the file server.

    Why it's wrong here

    A web application firewall inspects HTTP and HTTPS requests to protect web applications from attacks such as injection and cross-site scripting, and file shares do not use those protocols. It neither authenticates remote employees nor encrypts their sessions, so it cannot provide the secure remote access the business requires.

  • ✓

    A remote access VPN using TLS or IPsec.

    Why this is correct

    A remote access VPN authenticates the user and encrypts the entire session between the remote device and the corporate gateway, so file-share traffic is protected in transit without requiring per-application agents. It is well suited to a small business because it uses standard client software or a browser-based portal and centralizes access control at the VPN concentrator, meeting the authentication and encryption goals.

  • ✗

    A host-based intrusion prevention system on each laptop.

    Why it's wrong here

    A host-based intrusion prevention system monitors and blocks malicious activity on the endpoint itself, but it does not create a secure tunnel to internal file shares or authenticate the user to the corporate network. Deploying it on personal devices also raises privacy and management concerns, so it does not satisfy the remote access, authentication, and encryption requirements.

  • ✗

    A network access control solution enforcing 802.1X on the office switches.

    Why it's wrong here

    802.1X network access control governs which devices may connect to switch ports on the corporate LAN, so it has no effect on employees working from home over the internet. It authenticates devices at the edge of the wired or wireless network, not remote users, and it provides no confidentiality for file-share traffic traveling across public networks.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.