What Does a VPN Protect Between Headquarters and a Branch?
An organization is leveraging a VPN between its headquarters and a branch location. Which of the following is the VPN protecting?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the ability to distinguish between data states (in use vs. in transit), with the common trap being confusion with encryption used for stored data or regulatory compliance concepts like data sovereignty.
This question tests the fundamental understanding of data states and how Virtual Private Networks (VPNs) secure information during transmission. The community unanimously agrees that a VPN protects data in transit by encrypting traffic between two endpoints over an untrusted network.
Candidates often incorrectly select "Data in use," mistakenly associating VPN encryption with protecting active memory processes, or they choose "Data sovereignty" due to misinterpreting geographic routing features as legal protection mechanisms.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Data States and VPN Functionality
In cybersecurity, data exists in three primary states: data at rest, data in transit, and data in use. Understanding which security control applies to each state is a foundational CompTIA Security+ objective. A Virtual Private Network (VPN) establishes an encrypted tunnel over a public or untrusted network to securely connect two endpoints, such as a corporate headquarters and a remote branch office.Why Option B is Correct
A VPN explicitly protects data in transit. As highlighted by community experts, the primary function of a VPN is to encapsulate and encrypt packets moving across network boundaries, ensuring confidentiality and integrity during transmission. By creating a secure overlay network, the VPN prevents eavesdropping, man-in-the-middle attacks, and packet sniffing while data travels between locations. The unanimous community agreement confirms this direct mapping between VPNs and transit-state protection.Why the Other Options Are Incorrect
- Data in use refers to information actively being processed in system memory or CPU registers. Protecting data in use typically involves endpoint encryption, secure enclaves, or memory protection techniques, not network tunnels.
- Geographic restrictions involve access controls based on IP geolocation or content delivery networks (CDNs). While some VPNs can mask IP addresses, their core purpose is not enforcing regional compliance or bypassing geo-blocks.
- Data sovereignty is a legal/regulatory concept dictating where data must be stored and processed based on jurisdiction. A VPN provides cryptographic security but does not enforce legal boundaries or dictate physical data storage locations.
Community Consensus & Exam Context
Candidates universally selected Option B, recognizing the standard industry definition of VPN utility. Some users noted the straightforward nature of the question, while others cautioned against overcomplicating it with advanced networking features. For SY0-701, memorizing the three data states and matching them to appropriate controls will consistently yield correct answers.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives: Domain 2.3 - Network Security
- NIST SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
- RFC 4301: Security Architecture for the Internet Protocol (IPSec)
Exam Strategy
When faced with questions about security controls, first identify the state of the data mentioned in the scenario. Match the control to the data state using established frameworks rather than guessing based on peripheral features like routing or compliance keywords.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →