Courseiva

SSCP Network and Communications Security Practice Question

A security engineer is configuring an IPsec VPN between two offices to protect data in transit. The requirement is to ensure that packets cannot be modified or replayed by an attacker. Which security service should be enabled in the IPsec configuration?

⚠ Common exam trap

The trap here is assuming that ESP always provides integrity and replay protection, but ESP can be configured with confidentiality only, which lacks those services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication Header (AH)

The Authentication Header (AH) provides data integrity and authentication, and includes a sequence number to prevent replay attacks. In an IPsec VPN, AH ensures that packets cannot be altered in transit without detection. While ESP can also provide integrity and replay protection when configured with authentication, the scenario specifically asks for a service to prevent modification and replay, and AH is the dedicated protocol for that purpose. ESP is more commonly used because it also offers confidentiality, but AH alone meets the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Secure Hash Algorithm 2 (SHA-2) in tunnel mode

    Why it's wrong here

    SHA-2 is a hashing algorithm used within IPsec for integrity verification, but it is not a standalone security service. It must be combined with AH or ESP to provide integrity. Tunnel mode affects encapsulation but not the security services. Simply using SHA-2 without specifying AH or ESP does not guarantee integrity or replay protection for the packets.

  • ✓

    Authentication Header (AH)

    Why this is correct

    AH provides data integrity and authentication for IP packets, including protection against replay attacks by using a sequence number. It ensures that packets cannot be modified without detection. In this scenario, the requirement is specifically to prevent modification and replay, making AH the appropriate choice. However, AH does not provide confidentiality, so if encryption were also required, ESP would be needed.

  • ✗

    Internet Key Exchange (IKE) version 2

    Why it's wrong here

    IKEv2 is used to negotiate and establish security associations, including keys and algorithms. It does not directly protect data packets; rather, it sets up the IPsec tunnel. While IKEv2 can authenticate peers and provide replay protection for its own messages, it does not provide integrity or replay protection for the actual data traffic. Thus, it is not the service that ensures packet integrity.

  • ✗

    Encapsulating Security Payload (ESP) with confidentiality only

    Why it's wrong here

    ESP with confidentiality only encrypts the payload but does not provide integrity or replay protection. Without integrity, an attacker could modify encrypted packets, and the receiver might not detect it. Replay protection is also absent unless combined with authentication. Therefore, this option does not meet the requirement to prevent modification and replay, although ESP can provide those services when configured with authentication.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.