Cisco CCNA (200-301)Security FundamentalsMedium

Employees frequently travel and need secure encrypted access to internal company resources from any internet-connected location using a software client installed on their laptops. A permanent tunnel between fixed sites is not required. Which VPN type best meets this requirement?

  1. AGRE tunnel without encryption
  2. BClient-based remote-access VPN
  3. CSite-to-site VPN
  4. DMPLS VPN
Show answer & explanation

Correct answer: B. Client-based remote-access VPN

A client-based remote-access VPN (such as Cisco AnyConnect) allows individual users to establish an encrypted tunnel from any internet connection to the corporate network using client software, ideal for traveling employees needing on-demand access rather than a permanent site-to-site link.

Why the other options are wrong

  • A. GRE alone provides tunneling but no encryption, and it is not typically used for individual remote user access.
  • C. Site-to-site VPNs connect two fixed locations permanently and are not designed for individual traveling users.
  • D. MPLS VPNs are provider-managed private WAN circuits, not client-initiated encrypted tunnels for remote users.

Client-Based Remote-Access VPN

A VPN solution where individual users run client software (e.g., Cisco AnyConnect) to establish an encrypted tunnel to a corporate network from any internet connection, ideal for remote/traveling users.

  • Established on-demand by the user, not permanent
  • Commonly uses SSL/TLS or IPsec
  • Contrasts with site-to-site VPNs, which connect fixed locations permanently

Memory trick: Traveling employee = client software = remote-access VPN.

More Security Fundamentals questions