CompTIA Network+ (N10-009)Networking ConceptsMedium
A company wants remote employees working from home to securely access internal file servers over the public internet as if they were directly connected to the corporate LAN, with all traffic encrypted end-to-end. Which technology best meets this requirement?
- AVLAN trunking
- BClient-to-site VPN
- CReverse proxy
- DStatic NAT
Show answer & explanationAnswer & explanation
Correct answer: B. Client-to-site VPN
A client-to-site (remote-access) VPN, typically using IPsec or SSL/TLS, creates an encrypted tunnel between a remote user's device and the corporate network, allowing secure access to internal resources as if locally connected.
Why the other options are wrong
- A. VLAN trunking segments traffic within a LAN and does not provide remote encrypted access over the internet.
- C. A reverse proxy forwards external requests to internal servers but does not create an encrypted user tunnel.
- D. Static NAT maps a single public IP to a private IP but provides no encryption or tunneling.
Client-to-Site VPN
A VPN configuration that allows an individual remote device to establish an encrypted tunnel into a private network, granting secure access to internal resources.
- Also called remote-access VPN
- Commonly uses IPsec or SSL/TLS
- Differs from site-to-site VPN, which connects entire networks
Memory trick: One laptop, one tunnel — client-to-site is a private lane home to the office.