Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A development team frequently uses cloud-based services and needs to securely access internal corporate resources from various locations, including home offices and public Wi-Fi. The security policy mandates that all data in transit to corporate resources must be encrypted and that the integrity of the communication must be guaranteed. Which VPN technology provides both data confidentiality and integrity through strong encryption and hashing algorithms, suitable for this remote access scenario?

  1. APPTP (Point-to-Point Tunneling Protocol)
  2. BSSTP (Secure Socket Tunneling Protocol)
  3. CL2TP/IPsec (Layer 2 Tunneling Protocol over IPsec)
  4. DGRE (Generic Routing Encapsulation)
Show answer & explanation

Correct answer: C. L2TP/IPsec (Layer 2 Tunneling Protocol over IPsec)

L2TP/IPsec provides strong confidentiality through encryption (e.g., AES) and integrity through hashing (e.g., SHA) by encapsulating L2TP packets within an IPsec tunnel. PPTP offers weak encryption and no integrity. GRE is an encapsulation protocol without built-in encryption or integrity. SSTP uses SSL/TLS for encryption and integrity, but L2TP/IPsec is widely recognized for its robust security features meeting the stated requirements.

Why the other options are wrong

  • A. PPTP is considered insecure due to known vulnerabilities in its authentication and encryption mechanisms, making it unsuitable for secure remote access.
  • B. SSTP uses SSL/TLS for encryption and integrity, which is a viable option, but L2TP/IPsec is a more classic and widely used solution specifically designed for VPN security with strong confidentiality and integrity guarantees.
  • D. GRE is a tunneling protocol that encapsulates packets but does not provide encryption or integrity on its own; it often requires IPsec for security.

L2TP/IPsec VPN

A VPN protocol combining Layer 2 Tunneling Protocol (L2TP) for tunneling and IPsec for encryption, authentication, and integrity, commonly used for secure remote access.

  • Provides strong confidentiality (encryption).
  • Ensures data integrity (hashing).
  • Suitable for remote access scenarios.

Memory trick: To keep data secret and untouched, use IPsec's strong shield with a tunnel.

More Endpoint Security and Secure Network Access questions