ISC2 CC Network Security Practice Question
A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?
⚠ Common exam trap
Watch out — candidates often confuse endpoint security controls, such as host intrusion prevention, with the transport security and authentication that a remote access VPN actually provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A remote access VPN using TLS or IPsec.
A remote access VPN is designed exactly for this need: it authenticates the user at a central gateway and encrypts traffic between the remote device and the corporate network. The other choices address endpoint protection, local network admission control, or web application defense, none of which establish an authenticated, encrypted path to internal file shares for off-site workers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A web application firewall protecting the file server.
Why it's wrong here
A web application firewall inspects HTTP and HTTPS requests to protect web applications from attacks such as injection and cross-site scripting, and file shares do not use those protocols. It neither authenticates remote employees nor encrypts their sessions, so it cannot provide the secure remote access the business requires.
- ✓
A remote access VPN using TLS or IPsec.
Why this is correct
A remote access VPN authenticates the user and encrypts the entire session between the remote device and the corporate gateway, so file-share traffic is protected in transit without requiring per-application agents. It is well suited to a small business because it uses standard client software or a browser-based portal and centralizes access control at the VPN concentrator, meeting the authentication and encryption goals.
- ✗
A host-based intrusion prevention system on each laptop.
Why it's wrong here
A host-based intrusion prevention system monitors and blocks malicious activity on the endpoint itself, but it does not create a secure tunnel to internal file shares or authenticate the user to the corporate network. Deploying it on personal devices also raises privacy and management concerns, so it does not satisfy the remote access, authentication, and encryption requirements.
- ✗
A network access control solution enforcing 802.1X on the office switches.
Why it's wrong here
802.1X network access control governs which devices may connect to switch ports on the corporate LAN, so it has no effect on employees working from home over the internet. It authenticates devices at the edge of the wired or wireless network, not remote users, and it provides no confidentiality for file-share traffic traveling across public networks.
Go deeper
Related to this question
Learn chapter
Security Operations Basics
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.