hardMultiple Select
ISC2 CC Practice Question: Which THREE of the following are best practices…
Which THREE of the following are best practices for securing a remote access VPN?
⚠ Common exam trap
ISC2 often tests the misconception that pre-shared keys are acceptable for remote access VPNs because they are simple to configure, but the exam expects you to recognize that PSKs are a weak, shared secret that should be replaced with certificate-based or EAP authentication for secure remote access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable multi-factor authentication.
Option A (Enable multi-factor authentication) is correct because MFA adds a second verification factor beyond a password, so stolen or guessed credentials alone cannot establish a VPN session, directly mitigating credential-based attacks on remote access. Option B (Keep VPN client software up to date) is correct because VPN clients such as AnyConnect, GlobalProtect, or OpenVPN frequently receive patches for vulnerabilities (e.g., buffer overflows, TLS flaws), and running current versions closes known exploit paths on endpoints that terminate the tunnel. Option D (Enforce strong password policies) is correct because strong, complex, and rotated passwords reduce the risk of brute-force, credential-stuffing, and dictionary attacks against VPN authentication, complementing MFA as a defense-in-depth control. Option C (Use pre-shared keys for authentication) is not a best practice because PSKs are static secrets shared across users or devices, are difficult to rotate, and are vulnerable to theft and offline cracking, so they should be replaced by certificate-based or MFA-backed authentication. Option E (Implement split tunneling by default) is not a best practice because split tunneling lets remote traffic bypass the VPN and the corporate security stack, exposing the endpoint and internal network to threats; full tunneling or selective, policy-driven split tunneling is preferred.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable multi-factor authentication.
Why this is correct
Multi-factor authentication (MFA) satisfies the "best practices for securing a remote access VPN" constraint by enforcing a second verification factor—such as a time-based one-time password (TOTP) from an authenticator app or a biometric check—beyond the primary username and password. This mitigates credential theft risks inherent in VPN gateways exposed to the internet, as an attacker compromising a password still cannot authenticate without the second factor, which is typically validated against a directory service like Microsoft Entra ID.
- ✓
Keep VPN client software up to date.
Why this is correct
Patching the VPN client closes known vulnerabilities in the tunnelling software that attackers exploit for remote code execution or credential theft. Current clients also support modern ciphers and authentication methods, preserving the integrity of the encrypted tunnel.
- ✗
Use pre-shared keys for authentication.
Why it's wrong here
A pre-shared key is a static secret shared by every peer, so it cannot be revoked per user or tied to an individual identity, and compromise of one device exposes the whole group. It is tempting because PSKs are simple to deploy on site-to-site tunnels between fixed gateways, where certificate or per-user authentication is impractical.
- ✓
Enforce strong password policies.
Why this is correct
Strong password policies increase resistance to brute-force and credential-stuffing attacks against VPN gateways, which are internet-facing and heavily targeted. Complexity, length and rotation requirements reduce the likelihood that guessed or reused credentials grant an attacker authenticated tunnel access.
- ✗
Implement split tunneling by default.
Why it's wrong here
Split tunnelling routes only corporate-bound traffic through the tunnel, letting internet traffic bypass VPN inspection and filtering, which weakens endpoint and data-loss controls. It is tempting because it reduces tunnel bandwidth and latency for cloud and streaming traffic, making it a reasonable choice when policy permits direct internet access.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Transport Layer Security
Transport Layer Security (TLS) is a cryptographic protocol that provides secure, encrypted communication between two devices over a network, such as between a web browser and a server.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.