hardMultiple Choice
Which Protocol Secures Connections Between Data Centers Across an Untrusted WAN?
A network architect is designing a secure connection between two data centers across an untrusted WAN. The requirement is to encrypt all traffic and authenticate both endpoints. Which protocol should be used?
Quick Answer
IPsec tunnel mode is the correct choice because it encrypts the entire original IP packet, including its header, and wraps it in a new IP header for secure transport across an untrusted WAN, while also using IKE to mutually authenticate both data center endpoints. This protocol is specifically designed for secure site-to-site VPN connections between data centers, as it provides both confidentiality for all traffic and strong endpoint authentication, meeting the dual requirement of encrypting everything and verifying both sides. On the CISSP exam, this question tests your understanding of network security protocols in the Communication and Network Security domain, where a common trap is confusing IPsec tunnel mode with transport mode—remember that tunnel mode protects the whole packet for gateway-to-gateway links, while transport mode only encrypts the payload for host-to-host. A useful memory tip: think of tunnel mode as a secure armored car that hides the entire package inside a new outer wrapper, whereas transport mode is like a sealed envelope inside a clear bag.
⚠ Common exam trap
ISC2 often tests the distinction between IPsec tunnel mode and transport mode, and candidates may confuse SSL/TLS (which secures individual sessions) with a full network-layer VPN solution, missing that IPsec tunnel mode is the only option that encrypts all traffic and authenticates both endpoints at the network layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPsec tunnel mode
IPsec tunnel mode is the correct choice because it encrypts the entire IP packet, including the original IP header, and encapsulates it within a new IP header for secure transport across an untrusted WAN. It also provides mutual authentication of both endpoints using IKE (Internet Key Exchange) with pre-shared keys or certificates, satisfying the requirement for encrypting all traffic and authenticating both data centers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSH
Why it's wrong here
SSH secures interactive terminal sessions and file transfers, not bulk site-to-site traffic, and it authenticates users or hosts rather than both network endpoints. It tempts because SSH is a well-known encrypted remote-access protocol, but it cannot tunnel arbitrary data-centre traffic the way IPsec does.
- ✓
IPsec tunnel mode
Why this is correct
IPsec tunnel mode encrypts the entire original packet and encapsulates it, providing confidentiality and mutual endpoint authentication via IKE. This satisfies the requirement to protect all traffic across the untrusted WAN while verifying both data-centre gateways.
- ✗
MPLS
Why it's wrong here
MPLS provides traffic separation and quality-of-service guarantees but performs no encryption or endpoint authentication, leaving data readable across the untrusted WAN. It tempts because MPLS is a private, carrier-managed WAN often trusted for confidentiality, yet the stem explicitly demands cryptographic protection that IPsec supplies.
- ✗
SSL/TLS
Why it's wrong here
SSL/TLS encrypts application-layer sessions and authenticates servers to clients, but it does not encrypt all traffic between two data centres or mutually authenticate both network endpoints. It tempts because TLS secures web and API traffic, which is its purpose, yet site-to-site tunnelling requires IPsec.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
IPsec
IPsec is a suite of protocols used to secure Internet Protocol (IP) communications by encrypting and authenticating each IP packet in a data stream.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISSP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security architect is designing a secure communication channel between two remote sites over the internet. Which TWO of the following protocols should be used to ensure confidentiality, integrity, and authentication?
medium- A.PPTP
- B.SSL/TLS
- ✓ C.IPsec with ESP in tunnel mode
- D.MPLS
- ✓ E.L2TP over IPsec
Why C: IPsec with ESP in tunnel mode (C) is correct because ESP provides confidentiality through encryption and integrity/authentication via its authentication mechanisms, while tunnel mode encapsulates and protects the entire original IP packet between the two site gateways, making it ideal for site-to-site VPNs over untrusted networks. L2TP over IPsec (E) is correct because L2TP alone provides no encryption, but when combined with IPsec transport mode it delivers confidentiality, integrity, and authentication for the tunneled PPP traffic, a standard approach for secure remote-site connectivity. PPTP (A) is not acceptable because its authentication (MS-CHAPv2) and encryption (MPPE) are considered weak and broken. SSL/TLS (B) secures application-layer sessions such as HTTPS but is not the standard protocol for transparent site-to-site network-layer tunnels. MPLS (D) is a service-provider routing and traffic-engineering technology that does not itself provide cryptographic confidentiality, integrity, or authentication.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.