The answer to question 01: A client-to-site topology is used by many virtual private networks (VPNs), in which one or more hosts connect to a site (a remote access VPN). Site-to-site and host-to-host topologies are two other alternatives. The answer to question 02: Before the user transmits authentication credentials, Transport Layer Security (TLS) employs a digital certificate on the VPN gateway to authenticate the remote server and build an encrypted tunnel. The answer to question 03: Encapsulation Security Payload in Transport Mode (ESP). Tunnel mode encrypts the IP header information, although in a private network, this isn't necessary. Only authentication and integrity validation are provided by the Authentication Header, not confidentiality.