Courseiva
hardMultiple Choice

Which Protocol Secures Connections Between Data Centers Across an Untrusted WAN?

A network architect is designing a secure connection between two data centers across an untrusted WAN. The requirement is to encrypt all traffic and authenticate both endpoints. Which protocol should be used?

Quick Answer

IPsec tunnel mode is the correct choice because it encrypts the entire original IP packet, including its header, and wraps it in a new IP header for secure transport across an untrusted WAN, while also using IKE to mutually authenticate both data center endpoints. This protocol is specifically designed for secure site-to-site VPN connections between data centers, as it provides both confidentiality for all traffic and strong endpoint authentication, meeting the dual requirement of encrypting everything and verifying both sides. On the CISSP exam, this question tests your understanding of network security protocols in the Communication and Network Security domain, where a common trap is confusing IPsec tunnel mode with transport mode—remember that tunnel mode protects the whole packet for gateway-to-gateway links, while transport mode only encrypts the payload for host-to-host. A useful memory tip: think of tunnel mode as a secure armored car that hides the entire package inside a new outer wrapper, whereas transport mode is like a sealed envelope inside a clear bag.

⚠ Common exam trap

ISC2 often tests the distinction between IPsec tunnel mode and transport mode, and candidates may confuse SSL/TLS (which secures individual sessions) with a full network-layer VPN solution, missing that IPsec tunnel mode is the only option that encrypts all traffic and authenticates both endpoints at the network layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPsec tunnel mode

IPsec tunnel mode is the correct choice because it encrypts the entire IP packet, including the original IP header, and encapsulates it within a new IP header for secure transport across an untrusted WAN. It also provides mutual authentication of both endpoints using IKE (Internet Key Exchange) with pre-shared keys or certificates, satisfying the requirement for encrypting all traffic and authenticating both data centers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSH

    Why it's wrong here

    SSH secures interactive terminal sessions and file transfers, not bulk site-to-site traffic, and it authenticates users or hosts rather than both network endpoints. It tempts because SSH is a well-known encrypted remote-access protocol, but it cannot tunnel arbitrary data-centre traffic the way IPsec does.

  • ✓

    IPsec tunnel mode

    Why this is correct

    IPsec tunnel mode encrypts the entire original packet and encapsulates it, providing confidentiality and mutual endpoint authentication via IKE. This satisfies the requirement to protect all traffic across the untrusted WAN while verifying both data-centre gateways.

  • ✗

    MPLS

    Why it's wrong here

    MPLS provides traffic separation and quality-of-service guarantees but performs no encryption or endpoint authentication, leaving data readable across the untrusted WAN. It tempts because MPLS is a private, carrier-managed WAN often trusted for confidentiality, yet the stem explicitly demands cryptographic protection that IPsec supplies.

  • ✗

    SSL/TLS

    Why it's wrong here

    SSL/TLS encrypts application-layer sessions and authenticates servers to clients, but it does not encrypt all traffic between two data centres or mutually authenticate both network endpoints. It tempts because TLS secures web and API traffic, which is its purpose, yet site-to-site tunnelling requires IPsec.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security architect is designing a secure communication channel between two remote sites over the internet. Which TWO of the following protocols should be used to ensure confidentiality, integrity, and authentication?

medium
  • A.PPTP
  • B.SSL/TLS
  • ✓ C.IPsec with ESP in tunnel mode
  • D.MPLS
  • ✓ E.L2TP over IPsec

Why C: IPsec with ESP in tunnel mode (C) is correct because ESP provides confidentiality through encryption and integrity/authentication via its authentication mechanisms, while tunnel mode encapsulates and protects the entire original IP packet between the two site gateways, making it ideal for site-to-site VPNs over untrusted networks. L2TP over IPsec (E) is correct because L2TP alone provides no encryption, but when combined with IPsec transport mode it delivers confidentiality, integrity, and authentication for the tunneled PPP traffic, a standard approach for secure remote-site connectivity. PPTP (A) is not acceptable because its authentication (MS-CHAPv2) and encryption (MPPE) are considered weak and broken. SSL/TLS (B) secures application-layer sessions such as HTTPS but is not the standard protocol for transparent site-to-site network-layer tunnels. MPLS (D) is a service-provider routing and traffic-engineering technology that does not itself provide cryptographic confidentiality, integrity, or authentication.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.