Which encryption mode is used when a site-to-site VPN leaves the packet's IP address fields unencrypted?
Choose an answer
Tap an option to check your answer.
Correct answer: Transport.
Why this is the answer
Transport mode in IPsec (used for site-to-site VPNs) encrypts only the payload of the IP packet, leaving the original IP header unencrypted. This allows routers to still inspect and forward the packet based on its destination IP address. Tunnel mode, in contrast, encrypts the entire original IP packet and then encapsulates it within a new IP packet with a new header. PPTP (Point-to-Point Tunneling Protocol) is an older, less secure VPN protocol. Secure Shell (SSH) is primarily used for secure remote access and file transfer, not typically for site-to-site VPNs. PPPoE (Point-to-Point Protocol over Ethernet) is used for encapsulating PPP frames over Ethernet networks, commonly for DSL connections, and is not an encryption mode for VPNs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed