IPsec Tunnel Mode Encrypts the Entire Original Datagram
Which factor must be considered during the implementation of an IPsec VPN?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tunnel mode = encrypt everything (original IP header included) + new outer IP header; transport mode = encrypt payload only, original IP header preserved.
IPsec tunnel mode encrypts the whole original IP packet (header and payload) and wraps it with a new IP header, used for site-to-site and remote-access VPNs. Transport mode encrypts only the payload (L4 and up) and keeps the original IP header. GRE is a separate tunneling protocol, not made more secure by transport mode.
Picking C (that describes transport mode, not tunnel) or D (transport mode encrypts the L4 header too). B wrongly ties transport mode to GRE security.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A is correct. IPsec tunnel mode encrypts the entire original IP datagram (header and payload) and adds a new IP header for delivery to the tunnel endpoint.Why the Other Options Are Wrong
B is wrong: transport mode does not increase GRE security; GRE and IPsec are distinct. C is wrong: encrypting only the payload describes transport mode, not tunnel. D is wrong: transport mode encrypts the Layer 4 header along with the payload.Community Comment Notes
The vote is A (100). Commenters confirm 'the entire datagram is encrypted' in tunnel mode.Official Reference
Related Analysis
Practice All 200-301 Questions
Access 220 questions with complete answers and detailed explanations.
View Full 200-301 Practice Test →