A security engineer is configuring a site-to-site VPN between two branch offices using IPsec in tunnel mode. Which protocol provides both authentication and encryption of the entire original IP packet?
ESP in tunnel mode encapsulates the entire original IP packet and applies both encryption and authentication, satisfying the stem's dual requirement. AH provides authentication only, without confidentiality, so it cannot encrypt payloads. ESP's tunnel encapsulation also hides original source and destination addresses, which transport mode does not.
Why this answer
ESP (Encapsulating Security Payload) in tunnel mode encrypts and authenticates the entire original IP packet, then encapsulates it inside a new IP packet with new headers. This provides confidentiality, integrity, and origin authentication for the payload, making it the standard choice for site-to-site VPNs.
Exam trap
SSCP often tests the AH vs. ESP distinction — the trap is selecting AH for 'authentication' when the question also requires encryption, which only ESP provides.
How to eliminate wrong answers
Option A is wrong because IKEv2 is a key-exchange protocol (used to negotiate SAs), not a data-encryption protocol, and transport mode does not encapsulate the original IP header. Option C is wrong because L2TP provides no encryption on its own — it is typically paired with IPsec for confidentiality. Option D is wrong because AH provides authentication and integrity but no encryption, so it cannot satisfy the 'encryption' requirement.