ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 399 - CAS-004 discussion

Report
Export

A security administrator wants to enable a feature that would prevent a compromised encryption key from being used to decrypt all the VPN traffic. Which of the following should the security administrator use?

A.
Salsa20 cipher
Answers
A.
Salsa20 cipher
B.
TLS-based VPN
Answers
B.
TLS-based VPN
C.
PKI-based IKE IPSec negotiation
Answers
C.
PKI-based IKE IPSec negotiation
D.
Perfect forward secrecy
Answers
D.
Perfect forward secrecy
Suggested answer: D

Explanation:

Perfect Forward Secrecy (PFS) is a feature of certain key agreement protocols that ensures a session key derived from a set of long-term keys cannot be compromised if one of the long-term keys is compromised in the future. In the context of a VPN, PFS ensures that each session has a unique encryption key, and even if a key is compromised, it will not compromise past or future VPN sessions.

asked 02/10/2024
Francesco Mammola
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first