SSCP Network and Communications Security Practice Question
An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?
⚠ Common exam trap
The trap is choosing IPsec-based options (L2TP/IPsec or IPsec tunnel mode) for 'works through firewalls without additional ports,' when only SSL/TLS VPN on TCP 443 reliably meets that requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL/TLS VPN
SSL/TLS VPNs (e.g., clientless or client-based SSL VPNs) use TLS over TCP port 443, which is almost universally allowed through firewalls, and they support strong encryption (AES) and mutual authentication via certificates or client certificates. Because they ride on standard HTTPS, no additional ports need to be opened, satisfying all stated requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
L2TP/IPsec
Why it's wrong here
L2TP carries no encryption of its own and relies on IPsec, which uses ESP (IP protocol 50) and IKE over UDP 500/4500; many firewalls block these, breaching the no-extra-ports requirement. It is tempting because L2TP/IPsec does provide strong encryption and mutual authentication, making it correct when firewall traversal is not constrained.
- ✗
PPTP
Why it's wrong here
PPTP's MS-CHAPv2 authentication and RC4 encryption are cryptographically broken, failing the strong-encryption and mutual-authentication requirements. It is tempting because PPTP uses TCP port 1723 with GRE, traverses many firewalls, and is easy to configure, so it would suit a scenario where only basic tunnelling through NAT was needed.
- ✗
IPsec tunnel mode
Why it's wrong here
IPsec tunnel mode encrypts and authenticates gateway-to-gateway traffic but uses ESP (IP protocol 50) and IKE on UDP 500/4500, which many firewalls block, so it fails the no-extra-ports requirement. It is tempting because tunnel mode provides strong encryption and mutual authentication, making it correct for site-to-site links rather than client remote access.
- ✓
SSL/TLS VPN
Why this is correct
SSL/TLS VPN tunnels over TCP 443, so it traverses existing firewall rules without opening extra ports, satisfying that constraint. It supports strong encryption and mutual authentication through client certificates, letting the organisation verify both user and server identities during the remote access session.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?
easy- A.IPsec
- ✓ B.SSL/TLS VPN
- C.L2TP/IPsec
- D.PPTP
Why B: An SSL/TLS VPN uses TLS (typically over TCP port 443) to encrypt traffic and is the protocol underlying Cisco AnyConnect, which is a classic example of a client-based SSL VPN. It provides secure remote access without requiring IPsec's UDP ports, making it firewall-friendly.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.