ExamGecko
Question list
Search
Search

Question 905 - 200-301 discussion

Report
Export

Which IPsec encryption mode is appropriate when the destination of a packet differs from the security termination point?

A.

tunnel

Answers
A.

tunnel

B.

transport

Answers
B.

transport

C.

aggressive

Answers
C.

aggressive

D.

main

Answers
D.

main

Suggested answer: B

Explanation:

IPsec encryption mode is the way IPsec secures the data packets that are sent over an IP network.There are two main modes of IPsec encryption: tunnel mode and transport mode1.Tunnel mode encrypts the entire IP packet, including the original header, and adds a new IP header with the source and destination addresses of the security gateways (routers, firewalls, or VPN servers) that perform the encryption and decryption2.Transport mode encrypts only the payload (data) of the IP packet, leaving the original header intact, and uses the original source and destination addresses of the endpoints that generate and consume the data3. Therefore, transport mode is appropriate when the destination of a packet differs from the security termination point, as it does not change the original IP header information. Tunnel mode is more suitable when the security termination point is also the destination of the packet, as it provides more protection for the original IP header information.

asked 07/10/2024
Stelios Mantas
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first