CompTIA Network+ (N10-009)Network OperationsHard

Two branch offices require a permanent, always-on encrypted connection so that all users and servers on both networks can communicate transparently without installing individual VPN client software on each device. Which solution best meets this requirement?

  1. ASite-to-site VPN
  2. BSSH port forwarding
  3. CClient-to-site VPN
  4. DSplit-tunnel VPN
Show answer & explanation

Correct answer: A. Site-to-site VPN

A site-to-site VPN establishes a persistent encrypted tunnel between two gateway devices (routers/firewalls), allowing entire networks to communicate securely without requiring client software on individual endpoints. Client-to-site and split-tunnel VPNs are per-user solutions requiring client configuration, and SSH port forwarding only tunnels specific application traffic, not whole-network communication.

Why the other options are wrong

  • B. SSH port forwarding tunnels individual application sessions, not whole-network traffic.
  • C. Client-to-site VPN requires individual client software on each user's device, which contradicts the requirement.
  • D. Split-tunnel is a client VPN configuration choice, not a network-to-network solution.

Site-to-Site VPN

A VPN tunnel established between two network gateways (e.g., routers or firewalls) that transparently connects two networks over an encrypted channel, without requiring client software on individual devices.

  • Configured between gateway/firewall devices, not end-user clients
  • Provides always-on, transparent connectivity between branch networks
  • Contrasts with client-to-site VPN, which connects individual remote users

Memory trick: Site-to-site links whole buildings, not just people.

More Network Operations questions