Courseiva
mediumMultiple Select

SSCP Practice Question: Is implementing a new remote access VPN for…

An organization is implementing a new remote access VPN for employees using IPsec. Which TWO of the following are best practices for securing the IPsec VPN?

⚠ Common exam trap

Watch out — candidates often confuse pre-shared keys as a secure authentication method for IPsec, but the SSCP exam emphasizes that PSKs are weak compared to digital certificates or EAP methods, especially in enterprise environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AES encryption with a minimum key size of 128 bits

Option A is correct because AES with a minimum 128-bit key is a current, strong symmetric cipher standard for IPsec ESP, providing confidentiality that is resistant to brute-force attacks; 128-bit AES is the minimum acceptable, with 256-bit preferred for higher assurance. Option D is correct because enabling Perfect Forward Secrecy (PFS) via Diffie-Hellman (e.g., DH Group 14 or higher) ensures that compromise of a long-term key cannot decrypt previously captured session keys, limiting the blast radius of a key compromise. Option B is not a best practice because static pre-shared keys are weak, hard to rotate, and do not scale; certificate-based authentication (IKEv2 with X.509) or strong EAP methods should be used instead. Option C is wrong because disabling anti-replay protection removes a critical IPsec security feature that prevents attackers from capturing and retransmitting ESP packets, and the performance gain is negligible. Option E is wrong because allowing all IP protocols through the tunnel violates least-privilege and broadens the attack surface; traffic should be restricted by split-tunnel and firewall/ACL policy to only required protocols and subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AES encryption with a minimum key size of 128 bits

    Why this is correct

    AES with a 128-bit minimum key satisfies IPsec confidentiality requirements, since AES is the current standard block cipher and 128 bits resists brute force. DES and 3DES are deprecated, so this directly meets the best-practice constraint for the VPN.

  • ✗

    Use pre-shared keys for authentication

    Why it's wrong here

    Pre-shared keys are static secrets shared across peers; compromise of one endpoint exposes the tunnel to every peer using that key. Certificate-based authentication with IKEv2 provides per-peer identity and revocation. Pre-shared keys tempt for rapid deployment, but they lack the scalability and forward secrecy production VPNs need.

  • ✗

    Disable anti-replay protection to improve performance

    Why it's wrong here

    Anti-replay protection uses sequence numbers to discard duplicated or replayed packets; disabling it lets an attacker capture and resend valid ESP traffic, undermining integrity. It is tempting when packet loss or reordering causes drops, and disabling it would suit a lab or troubleshooting scenario, never a production VPN.

  • ✓

    Enable Perfect Forward Secrecy (PFS)

    Why this is correct

    Perfect Forward Secrecy generates a unique session key for each IPsec phase 2 negotiation, so compromising one key cannot decrypt previously captured traffic. This satisfies the stem's requirement for securing the VPN against retrospective decryption, since an attacker who later obtains the long-term key still cannot recover earlier session data.

  • ✗

    Allow all IP protocols through the VPN tunnel

    Why it's wrong here

    Permitting every IP protocol through the tunnel removes the security policy that restricts traffic to required ports and services, widening the attack surface. It is tempting because a permissive tunnel avoids troubleshooting blocked applications, and such broad traversal suits trusted site-to-site links where all internal traffic must pass unfiltered.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.