nerdexam
Check_Point

156-315.76 · Question #395

Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements…

The correct answer is D. IKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash. See the full explanation below for the reasoning.

Question

Yoav is a Security Administrator preparing to implement a VPN solution for his multi-site organization. To comply with industry regulations, Yoav's VPN solution must meet the following requirements:

Portability: Standard Key management: Automatic, external PKI Session keys: Changed at configured times during a connection's lifetime Key length: No less than 128-bit Data integrity: Secure against inversion and brute force attacks What is the most appropriate setting Yoav should choose?

Options

  • AIKE VPNs: AES encryption for IKE Phase 1, and DES encryption for Phase 2; SHA1 hash
  • BIKE VPNs: SHA1 encryption for IKE Phase 1, and MD5 encryption for Phase 2; AES hash
  • CIKE VPNs: CAST encryption for IKE Phase 1, and SHA1 encryption for Phase 2; DES hash
  • DIKE VPNs: AES encryption for IKE Phase 1, and AES encryption for Phase 2; SHA1 hash
  • EIKE VPNs: DES encryption for IKE Phase 1, and 3DES encryption for Phase 2; MD5 hash

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    11% (2)
  • C
    5% (1)
  • D
    79% (15)

Community Discussion

No community discussion yet for this question.

Full 156-315.76 Practice