SSCP Network and Communications Security Practice Question
A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?
⚠ Common exam trap
The trap is selecting L2TP or PPTP as they are VPN protocols, but they lack strong encryption or have known vulnerabilities. Candidates must recognize that EAP-TLS, IPsec tunnel mode, and IKEv2 are the secure components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EAP-TLS for authentication
EAP-TLS (B) is correct because it uses digital certificates on both client and server to perform mutual authentication, providing strong identity verification and enabling the certificate-based trust needed to resist impersonation. IPsec in tunnel mode (C) is correct because it encrypts and authenticates the entire original IP packet between endpoints, protecting confidentiality and integrity of the traffic across an untrusted network. IKEv2 (E) is correct because it securely negotiates and rekeys IPsec security associations using strong cryptographic exchanges, and its support for MOBIKE helps maintain secure sessions while resisting man-in-the-middle interception. L2TP (A) is not correct here because by itself it provides tunneling but no encryption or strong authentication, so it must be paired with IPsec rather than being the security component. PPTP with MPPE (D) is not correct because PPTP is obsolete and its MS-CHAPv2 authentication and MPPE encryption have well-known weaknesses that make it vulnerable to credential cracking and MITM attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
L2TP tunneling protocol
Why it's wrong here
L2TP provides only tunnelling and no encryption or authentication of its own; it must be paired with IPsec to satisfy the strong authentication and man-in-the-middle resistance requirements. It is tempting because L2TP/IPsec is a legitimate secure combination, but L2TP alone, as listed here, supplies no cryptographic protection.
- ✓
EAP-TLS for authentication
Why this is correct
EAP-TLS authenticates both client and server using X.509 certificates, delivering mutual authentication without shared secrets. This satisfies the stem's strong authentication requirement and, because the server proves its identity, resists man-in-the-middle attacks against the remote access tunnel.
- ✓
IPsec in tunnel mode
Why this is correct
IPsec in tunnel mode encrypts the entire original packet, including headers, then encapsulates it within a new IP header between gateways. This satisfies the encryption and man-in-the-middle resistance requirements, as tampered packets fail authentication checks. Combined with strong authentication via IKE, it secures remote laptop traffic across untrusted networks.
- ✗
PPTP with MPPE encryption
Why it's wrong here
PPTP's MPPE encryption is cryptographically broken, and PPTP itself lacks a mechanism binding the tunnel to a mutually authenticated endpoint, so it cannot resist man-in-the-middle attacks. It is tempting as a legacy Windows VPN protocol that is easy to deploy, and would suffice only where confidentiality against casual interception is the sole requirement.
- ✓
IKEv2 key exchange protocol
Why this is correct
IKEv2 performs mutual authentication during tunnel establishment and negotiates fresh session keys, so a man-in-the-middle cannot impersonate either endpoint. This satisfies the stem's resistance to man-in-the-middle attacks while supporting strong authentication and encryption for the remote access design.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.