Which IPsec mode encrypts the entire original IP packet?
Choose an answer
Tap an option to check your answer.
Correct answer: tunnel.
Why this is the answer
Tunnel mode encrypts the entire original IP packet, including the original IP header, and then encapsulates it within a new IP packet with a new IP header. This provides end-to-end encryption and is commonly used for site-to-site VPNs. Transport mode, in contrast, only encrypts the payload of the original IP packet, leaving the original IP header unencrypted. This mode is typically used for host-to-host or host-to-gateway connections where the original IP header information is needed for routing. "Pipe" and "control" are not standard IPsec modes.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed