SSCP Network and Communications Security Practice Question
A security engineer is configuring an IPsec VPN between two offices to protect data in transit. The requirement is to ensure that packets cannot be modified or replayed by an attacker. Which security service should be enabled in the IPsec configuration?
⚠ Common exam trap
The trap here is assuming that ESP always provides integrity and replay protection, but ESP can be configured with confidentiality only, which lacks those services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication Header (AH)
The Authentication Header (AH) provides data integrity and authentication, and includes a sequence number to prevent replay attacks. In an IPsec VPN, AH ensures that packets cannot be altered in transit without detection. While ESP can also provide integrity and replay protection when configured with authentication, the scenario specifically asks for a service to prevent modification and replay, and AH is the dedicated protocol for that purpose. ESP is more commonly used because it also offers confidentiality, but AH alone meets the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secure Hash Algorithm 2 (SHA-2) in tunnel mode
Why it's wrong here
SHA-2 is a hashing algorithm used within IPsec for integrity verification, but it is not a standalone security service. It must be combined with AH or ESP to provide integrity. Tunnel mode affects encapsulation but not the security services. Simply using SHA-2 without specifying AH or ESP does not guarantee integrity or replay protection for the packets.
- ✓
Authentication Header (AH)
Why this is correct
AH provides data integrity and authentication for IP packets, including protection against replay attacks by using a sequence number. It ensures that packets cannot be modified without detection. In this scenario, the requirement is specifically to prevent modification and replay, making AH the appropriate choice. However, AH does not provide confidentiality, so if encryption were also required, ESP would be needed.
- ✗
Internet Key Exchange (IKE) version 2
Why it's wrong here
IKEv2 is used to negotiate and establish security associations, including keys and algorithms. It does not directly protect data packets; rather, it sets up the IPsec tunnel. While IKEv2 can authenticate peers and provide replay protection for its own messages, it does not provide integrity or replay protection for the actual data traffic. Thus, it is not the service that ensures packet integrity.
- ✗
Encapsulating Security Payload (ESP) with confidentiality only
Why it's wrong here
ESP with confidentiality only encrypts the payload but does not provide integrity or replay protection. Without integrity, an attacker could modify encrypted packets, and the receiver might not detect it. Replay protection is also absent unless combined with authentication. Therefore, this option does not meet the requirement to prevent modification and replay, although ESP can provide those services when configured with authentication.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.