nerdexam
Check_Point

156-915.77 · Question #190

(Topic 15) If you need strong protection for the encryption of user data, what option would be the BEST choice?

The correct answer is C. Use certificates for Phase 1, SHA for all hashes, AES for all encryption and PFS, and. Fill in the blank. To remove site-to-site IKE and IPSEC keys you would enter command ____ ___ and select the option to delete all IKE and IPSec SA's.

Advanced VPN and Remote Access Solutions

Question

  • (Topic 15)

If you need strong protection for the encryption of user data, what option would be the BEST choice?

Options

  • AUse Diffie-Hellman for key construction and pre-shared keys for Quick Mode. Choose
  • BWhen you need strong encryption, IPsec is not the best choice. SSL VPN's are a better
  • CUse certificates for Phase 1, SHA for all hashes, AES for all encryption and PFS, and
  • DDisable Diffie-Hellman by using stronger certificate based key-derivation. Use AES-256

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    15% (8)
  • C
    71% (39)
  • D
    9% (5)

Explanation

Fill in the blank. To remove site-to-site IKE and IPSEC keys you would enter command ____ ___ and select the option to delete all IKE and IPSec SA's.

Topics

#IPsec encryption#certificates#AES#Perfect Forward Secrecy

Community Discussion

No community discussion yet for this question.

Full 156-915.77 Practice