Which IPsec mode is used when a packet's destination differs from the security termination point?
Choose an answer
Tap an option to check your answer.
Correct answer: tunnel.
Why this is the answer
Tunnel mode is correct because it encrypts the entire original IP packet, including its header, and then encapsulates it within a new IP packet with a new header. This is necessary when the security termination point (e.g., a VPN gateway) is not the final destination of the packet. The new IP header contains the addresses of the tunnel endpoints, allowing the packet to traverse intermediate networks securely. Transport mode, in contrast, only encrypts the payload of the original IP packet and keeps the original IP header. It's used when the security termination point is also the final destination. Main mode and aggressive mode are phases of the IKE (Internet Key Exchange) protocol, used for establishing security associations, not for defining how IP packets are encapsulated.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed