ISC2 CC Network Security Practice Question
A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?
⚠ Common exam trap
The trap here is focusing only on user authentication and overlooking the explicit requirement to verify device health before granting access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a remote access VPN that authenticates users and then performs a posture check before allowing access to the repository subnet.
A remote access VPN authenticates each developer and can enforce a posture check that verifies device health before allowing access to internal repositories. The repositories stay on an internal subnet and are not published to the internet. A reverse proxy with basic authentication, a site-to-site tunnel to home routers, and a jump host without device checks each fail at least one requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Expose the repositories through a jump host with SSH key authentication and no device checks.
Why it's wrong here
A jump host with SSH keys authenticates the developer's key but does not assess whether the laptop is patched, running endpoint protection, or otherwise healthy. It also places the jump host on the public internet, which increases exposure. The requirement explicitly includes device health verification, so this option is incomplete.
- ✗
Use a site-to-site IPsec tunnel between each developer's home router and the corporate gateway.
Why it's wrong here
A site-to-site IPsec tunnel is designed for fixed network-to-network connections, not for individual remote workers on varying home networks. It authenticates the home router, not the developer, and it does not evaluate the health of the developer's laptop. This approach also creates management overhead for each home router and does not meet the identity or posture requirements.
- ✗
Publish the code repositories through a reverse proxy with HTTP basic authentication.
Why it's wrong here
A reverse proxy with basic authentication verifies a username and password but does not check device health, and basic authentication sends credentials in an easily decoded form unless TLS is strictly enforced. It also exposes the repository service through the proxy rather than keeping it off the public internet. This fails the device health requirement and weakens identity assurance.
- ✓
Deploy a remote access VPN that authenticates users and then performs a posture check before allowing access to the repository subnet.
Why this is correct
A remote access VPN authenticates each developer and can integrate a posture or host-check step that evaluates device health before granting network access. The repositories remain on an internal subnet that is not directly reachable from the internet. This satisfies identity verification, device health assessment, and non-exposure of the repositories in one design.
Visual reference
Go deeper
Related to this question
Learn chapter
Wireless and Remote Access Security
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.