Which statement about IPsec modes is correct when implementing an IPsec VPN?
Choose an answer
Tap an option to check your answer.
Correct answer: In IPsec tunnel mode, the entire original IP datagram is encrypted..
Why this is the answer
In IPsec tunnel mode, the entire original IP packet (header and payload) is encrypted and then encapsulated with a new IP header. This provides the highest level of security as the original source and destination IP addresses are hidden. IPsec transport mode encrypts only the IP payload, leaving the original IP header intact. This means the original source and destination IP addresses are visible, which is less secure than tunnel mode but can be useful for host-to-host communication or when another tunneling protocol (like GRE) is already providing encapsulation. IPsec transport mode does not inherently increase GRE tunnel security over tunnel mode; in fact, tunnel mode generally offers stronger encapsulation. IPsec transport mode encrypts the Layer 4 header along with the payload, not leaving it unencrypted.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed