Courseiva

SSCP Network and Communications Security Practice Question

An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?

⚠ Common exam trap

The trap is choosing IPsec-based options (L2TP/IPsec or IPsec tunnel mode) for 'works through firewalls without additional ports,' when only SSL/TLS VPN on TCP 443 reliably meets that requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSL/TLS VPN

SSL/TLS VPNs (e.g., clientless or client-based SSL VPNs) use TLS over TCP port 443, which is almost universally allowed through firewalls, and they support strong encryption (AES) and mutual authentication via certificates or client certificates. Because they ride on standard HTTPS, no additional ports need to be opened, satisfying all stated requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    L2TP/IPsec

    Why it's wrong here

    L2TP carries no encryption of its own and relies on IPsec, which uses ESP (IP protocol 50) and IKE over UDP 500/4500; many firewalls block these, breaching the no-extra-ports requirement. It is tempting because L2TP/IPsec does provide strong encryption and mutual authentication, making it correct when firewall traversal is not constrained.

  • ✗

    PPTP

    Why it's wrong here

    PPTP's MS-CHAPv2 authentication and RC4 encryption are cryptographically broken, failing the strong-encryption and mutual-authentication requirements. It is tempting because PPTP uses TCP port 1723 with GRE, traverses many firewalls, and is easy to configure, so it would suit a scenario where only basic tunnelling through NAT was needed.

  • ✗

    IPsec tunnel mode

    Why it's wrong here

    IPsec tunnel mode encrypts and authenticates gateway-to-gateway traffic but uses ESP (IP protocol 50) and IKE on UDP 500/4500, which many firewalls block, so it fails the no-extra-ports requirement. It is tempting because tunnel mode provides strong encryption and mutual authentication, making it correct for site-to-site links rather than client remote access.

  • ✓

    SSL/TLS VPN

    Why this is correct

    SSL/TLS VPN tunnels over TCP 443, so it traverses existing firewall rules without opening extra ports, satisfying that constraint. It supports strong encryption and mutual authentication through client certificates, letting the organisation verify both user and server identities during the remote access session.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?

easy
  • A.IPsec
  • ✓ B.SSL/TLS VPN
  • C.L2TP/IPsec
  • D.PPTP

Why B: An SSL/TLS VPN uses TLS (typically over TCP port 443) to encrypt traffic and is the protocol underlying Cisco AnyConnect, which is a classic example of a client-based SSL VPN. It provides secure remote access without requiring IPsec's UDP ports, making it firewall-friendly.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.