Courseiva
Network Security →easyMultiple Choice

ISC2 CC Network Security Practice Question

A small business wants to provide secure remote access to its internal file server for employees working from home. The company requires that all traffic between the employee's device and the file server be encrypted and that the internal network topology remain hidden. Which technology best meets these requirements?

⚠ Common exam trap

The trap here is assuming any encrypted protocol (like SSH or HTTPS) provides equivalent remote access; only a VPN creates a network-level tunnel that hides internal topology and supports multiple services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN

A VPN is designed to provide encrypted, tunneled access to an entire network, making it ideal for remote employees who need to reach internal resources securely. It encapsulates traffic, encrypts it, and masks internal addresses, fulfilling both the encryption and topology-hiding requirements. Other options are protocol-specific and cannot deliver equivalent network-level access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPN

    Why this is correct

    A virtual private network (VPN) creates an encrypted tunnel between the remote user and the corporate network, protecting data in transit and hiding internal IP addresses. It allows employees to access internal resources as if they were on-site. This directly satisfies the requirement for encrypted communication and concealment of the internal network topology.

  • ✗

    HTTPS

    Why it's wrong here

    HTTPS encrypts web traffic between a browser and a web server, but it does not provide a general-purpose tunnel for file server access or other protocols. It also does not hide internal network topology; the client still connects directly to the server's IP or hostname. HTTPS is limited to web applications and would not enable access to a file share.

  • ✗

    SSH

    Why it's wrong here

    SSH provides encrypted remote command-line access to a single host, but it does not tunnel arbitrary network traffic or provide full network access. It cannot hide the internal network topology or give access to multiple resources like a file server share. While secure, SSH alone does not meet the broad remote access requirement.

  • ✗

    SFTP

    Why it's wrong here

    SFTP secures file transfers over SSH, but it only protects the file transfer session itself. It does not encrypt all traffic between the device and the internal network, nor does it hide the internal topology. Employees could transfer files, but they would not have full network access, and other traffic would remain unencrypted.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.