Question 1
Why would you create a VPN?
A VPN is created to encrypt data for secure transport across an untrusted or shared network. It establishes a protected tunnel between endpoints, users, sites, or networks so that traffic is less exposed to interception or tampering. Blocking malicious traffic is primarily the role of firewalls, IPS, secure web gateways, or other enforcement controls. Reducing traffic overhead is not the purpose of VPN; encryption can actually add overhead. Automating and correlating incidents is a SOAR or SIEM function, not VPN. VPNs are commonly used for remote user access and site-to-site connectivity. They can protect sensitive business communication between branch offices, cloud networks, and corporate resources. However, VPNs are not a complete security architecture by themselves. Strong authentication, access control, logging, least privilege, device posture validation, and segmentation are still necessary to ensure that encrypted access is also authorized and monitored. Reference/topics: Network Security 3.3, VPNs; Network Security 3.4, tunneling protocols.