Check_Point
156-315.76 · Question #395
Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements…
The correct answer is D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash. See the full explanation below for the reasoning.
Question
Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements:
Portability: Standard Key management: Automatic, external PKI Session keys: Changed at configured times during a connection's lifetime Key length: No less than 128-bit Data integrity: Secure against inversion and brute force attacks What is the most appropriate setting Yoav should choose?
Options
- AIKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash
- BIKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash
- CIKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash
- DIKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash
- EIKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash
How the community answered
(19 responses)- A5% (1)
- B11% (2)
- C5% (1)
- D79% (15)
Community Discussion
No community discussion yet for this question.