Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementEasy

A company is implementing a new security policy that requires all remote users to establish a secure, encrypted tunnel to the corporate network before accessing any internal resources. The solution must support various operating systems and devices, including laptops and mobile phones, without requiring extensive client software installation or hardware tokens. Which VPN technology best meets these requirements?

  1. ARemote Access SSL VPN
  2. BRemote Access IPsec VPN with IKEv2
  3. CGRE over IPsec VPN
  4. DSite-to-site IPsec VPN
Show answer & explanation

Correct answer: A. Remote Access SSL VPN

Remote Access SSL VPNs are ideal for this scenario because they use standard web browsers for connectivity, reducing the need for extensive client software installation and supporting a wide range of devices and operating systems. They provide encrypted tunnels over HTTPS.

Why the other options are wrong

  • B. While Remote Access IPsec VPNs provide strong security, they often require specific client software and can be more complex to configure across various operating systems compared to SSL VPNs.
  • C. GRE over IPsec VPNs are typically used for site-to-site connections or routing protocols over VPN, not primarily for individual remote user access.
  • D. Site-to-site IPsec VPNs connect entire networks, not individual remote users, and typically require dedicated hardware or software at each site.

Remote Access SSL VPN

A Virtual Private Network (VPN) solution that uses the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol to provide secure, encrypted remote access to a network for individual users.

  • Often browser-based or uses a lightweight client.
  • Highly compatible with various operating systems and devices.
  • Leverages HTTPS for encrypted communication.

Memory trick: Connecting from afar? Pick the right secure tunnel.

More Visibility and Enforcement questions