サイト間 VPN が構成されている場合、元の IP パケット全体のカプセル化と暗号化を提供する IPsec モードはどれですか。
正解:C
Answer C is the technically correct selection. IPsec tunnel mode with ESP encapsulates and encrypts the original IP packet for site-to-site VPN use. Tunnel mode wraps the entire inner packet with a new outer IP header, while ESP provides confidentiality and integrity protection for the protected payload. This aligns with Cisco CCNA 200-301 v1.1 because the exam blueprint requires engineers to recognize operational behaviour from configuration symptoms and topology requirements. AH does not provide encryption, and transport mode protects only the transport payload rather than the whole original packet. Treat the distractors carefully: most are real Cisco terms, but they solve a different problem or operate at a different layer. The selected answer is the one that would be used by an engineer on the device or in the design to produce the outcome stated in the question.