Courseiva

SSCP Network and Communications Security Practice Question

A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?

⚠ Common exam trap

The trap is selecting L2TP or PPTP as they are VPN protocols, but they lack strong encryption or have known vulnerabilities. Candidates must recognize that EAP-TLS, IPsec tunnel mode, and IKEv2 are the secure components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EAP-TLS for authentication

EAP-TLS (B) is correct because it uses digital certificates on both client and server to perform mutual authentication, providing strong identity verification and enabling the certificate-based trust needed to resist impersonation. IPsec in tunnel mode (C) is correct because it encrypts and authenticates the entire original IP packet between endpoints, protecting confidentiality and integrity of the traffic across an untrusted network. IKEv2 (E) is correct because it securely negotiates and rekeys IPsec security associations using strong cryptographic exchanges, and its support for MOBIKE helps maintain secure sessions while resisting man-in-the-middle interception. L2TP (A) is not correct here because by itself it provides tunneling but no encryption or strong authentication, so it must be paired with IPsec rather than being the security component. PPTP with MPPE (D) is not correct because PPTP is obsolete and its MS-CHAPv2 authentication and MPPE encryption have well-known weaknesses that make it vulnerable to credential cracking and MITM attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    L2TP tunneling protocol

    Why it's wrong here

    L2TP provides only tunnelling and no encryption or authentication of its own; it must be paired with IPsec to satisfy the strong authentication and man-in-the-middle resistance requirements. It is tempting because L2TP/IPsec is a legitimate secure combination, but L2TP alone, as listed here, supplies no cryptographic protection.

  • ✓

    EAP-TLS for authentication

    Why this is correct

    EAP-TLS authenticates both client and server using X.509 certificates, delivering mutual authentication without shared secrets. This satisfies the stem's strong authentication requirement and, because the server proves its identity, resists man-in-the-middle attacks against the remote access tunnel.

  • ✓

    IPsec in tunnel mode

    Why this is correct

    IPsec in tunnel mode encrypts the entire original packet, including headers, then encapsulates it within a new IP header between gateways. This satisfies the encryption and man-in-the-middle resistance requirements, as tampered packets fail authentication checks. Combined with strong authentication via IKE, it secures remote laptop traffic across untrusted networks.

  • ✗

    PPTP with MPPE encryption

    Why it's wrong here

    PPTP's MPPE encryption is cryptographically broken, and PPTP itself lacks a mechanism binding the tunnel to a mutually authenticated endpoint, so it cannot resist man-in-the-middle attacks. It is tempting as a legacy Windows VPN protocol that is easy to deploy, and would suffice only where confidentiality against casual interception is the sole requirement.

  • ✓

    IKEv2 key exchange protocol

    Why this is correct

    IKEv2 performs mutual authentication during tunnel establishment and negotiates fresh session keys, so a man-in-the-middle cannot impersonate either endpoint. This satisfies the stem's resistance to man-in-the-middle attacks while supporting strong authentication and encryption for the remote access design.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.