For a site-to-site VPN, which IPsec mode encapsulates and encrypts the entire original IP packet?
Choose an answer
Tap an option to check your answer.
Correct answer: IPsec tunnel mode with ESP.
Why this is the answer
IPsec tunnel mode with ESP is the correct answer. In tunnel mode, the entire original IP packet (header and payload) is encapsulated and encrypted. A new IP header is then added for routing across the network. ESP (Encapsulating Security Payload) provides confidentiality (encryption), data origin authentication, data integrity, and anti-replay services. This combination is ideal for site-to-site VPNs where the entire internal network traffic needs protection. IPsec transport mode only encrypts the payload of the original IP packet, leaving the original IP header exposed. This is typically used for host-to-host communication, not site-to-site VPNs. AH (Authentication Header) provides authentication and integrity but does not offer encryption, making it unsuitable for confidentiality requirements in VPNs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed