mediumMultiple Select
SSCP Practice Question: Is implementing a new remote access VPN for…
An organization is implementing a new remote access VPN for employees using IPsec. Which TWO of the following are best practices for securing the IPsec VPN?
⚠ Common exam trap
Watch out — candidates often confuse pre-shared keys as a secure authentication method for IPsec, but the SSCP exam emphasizes that PSKs are weak compared to digital certificates or EAP methods, especially in enterprise environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AES encryption with a minimum key size of 128 bits
Option A is correct because AES with a minimum 128-bit key is a current, strong symmetric cipher standard for IPsec ESP, providing confidentiality that is resistant to brute-force attacks; 128-bit AES is the minimum acceptable, with 256-bit preferred for higher assurance. Option D is correct because enabling Perfect Forward Secrecy (PFS) via Diffie-Hellman (e.g., DH Group 14 or higher) ensures that compromise of a long-term key cannot decrypt previously captured session keys, limiting the blast radius of a key compromise. Option B is not a best practice because static pre-shared keys are weak, hard to rotate, and do not scale; certificate-based authentication (IKEv2 with X.509) or strong EAP methods should be used instead. Option C is wrong because disabling anti-replay protection removes a critical IPsec security feature that prevents attackers from capturing and retransmitting ESP packets, and the performance gain is negligible. Option E is wrong because allowing all IP protocols through the tunnel violates least-privilege and broadens the attack surface; traffic should be restricted by split-tunnel and firewall/ACL policy to only required protocols and subnets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AES encryption with a minimum key size of 128 bits
Why this is correct
AES with a 128-bit minimum key satisfies IPsec confidentiality requirements, since AES is the current standard block cipher and 128 bits resists brute force. DES and 3DES are deprecated, so this directly meets the best-practice constraint for the VPN.
- ✗
Use pre-shared keys for authentication
Why it's wrong here
Pre-shared keys are static secrets shared across peers; compromise of one endpoint exposes the tunnel to every peer using that key. Certificate-based authentication with IKEv2 provides per-peer identity and revocation. Pre-shared keys tempt for rapid deployment, but they lack the scalability and forward secrecy production VPNs need.
- ✗
Disable anti-replay protection to improve performance
Why it's wrong here
Anti-replay protection uses sequence numbers to discard duplicated or replayed packets; disabling it lets an attacker capture and resend valid ESP traffic, undermining integrity. It is tempting when packet loss or reordering causes drops, and disabling it would suit a lab or troubleshooting scenario, never a production VPN.
- ✓
Enable Perfect Forward Secrecy (PFS)
Why this is correct
Perfect Forward Secrecy generates a unique session key for each IPsec phase 2 negotiation, so compromising one key cannot decrypt previously captured traffic. This satisfies the stem's requirement for securing the VPN against retrospective decryption, since an attacker who later obtains the long-term key still cannot recover earlier session data.
- ✗
Allow all IP protocols through the VPN tunnel
Why it's wrong here
Permitting every IP protocol through the tunnel removes the security policy that restricts traffic to required ports and services, widening the attack surface. It is tempting because a permissive tunnel avoids troubleshooting blocked applications, and such broad traversal suits trusted site-to-site links where all internal traffic must pass unfiltered.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.