nerdexam
Check_Point

156-215.71 · Question #280

Multi-Corp must comply with industry regulations in implementing VPN solutions among multiple sites. The corporate Information Assurance policy defines the following requirements: What is the most…

The correct answer is D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash. See the full explanation below for the reasoning.

Question

Multi-Corp must comply with industry regulations in implementing VPN solutions among multiple sites. The corporate Information Assurance policy defines the following requirements:

What is the most appropriate setting to comply with these requirements? Portability Standard Key management Automatic, external PKI Session keys changed at configured times during a connection's lifetime Key length No less than 128-bit Data integrity Secure against inversion and brute-force attacks What is the most appropriate setting to comply with theses requirements?

Options

  • AIKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for phase 2, AES hash
  • BIKE VPNs: DES encryption for IKE phase 1, and 3DES encryption for phase 2, MD 5 hash
  • CIKE VPNs: CAST encryption for IKE Phase 1, and SHA 1 encryption for phase 2, DES hash
  • DIKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    3% (1)
  • D
    77% (27)

Community Discussion

No community discussion yet for this question.

Full 156-215.71 Practice