nerdexam
Oracle

1Z0-820 · Question #74

Identify the two security features incorporated in the Oracle Solaris 11 Cryptographic Framework.

The correct answer is B. Internet protocol security D. Signed cryptographic plugins (providers). Oracle Solaris 11's Cryptographic Framework incorporates IPsec (B) for network-layer encryption and authentication, securing IP communications end-to-end, and signed cryptographic plugins/providers (D), which require all cryptographic modules loaded into the framework to carry…

Configuring and Administering Networks

Question

Identify the two security features incorporated in the Oracle Solaris 11 Cryptographic Framework.

Options

  • ALayer 5 IP address encryptions
  • BInternet protocol security
  • CDiffie-Kerberos coaxial key encryption
  • DSigned cryptographic plugins (providers)
  • EKernel support for signed antivirus plugins

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    86% (12)
  • E
    7% (1)

Explanation

Oracle Solaris 11's Cryptographic Framework incorporates IPsec (B) for network-layer encryption and authentication, securing IP communications end-to-end, and signed cryptographic plugins/providers (D), which require all cryptographic modules loaded into the framework to carry a verified digital signature - preventing tampered or malicious providers from being used.

Why the distractors are wrong:

  • A is fabricated; "Layer 5 IP address encryption" is not a real security concept - Layer 5 (Session) doesn't perform IP address encryption.
  • C is nonsense; "Diffie-Kerberos coaxial key encryption" combines real terms (Diffie-Hellman key exchange, Kerberos authentication) with an unrelated word ("coaxial" is a cable type) to sound plausible.
  • E is a near-miss trap; the framework does use signed plugins, but they are cryptographic providers, not antivirus plugins.

Memory tip: Think of the Solaris Cryptographic Framework as a trusted vault with a bouncer - IPsec secures the network traffic moving in and out, while signed providers ensure only verified, tamper-proof crypto modules are allowed inside the vault.

Topics

#Cryptographic Framework#IPsec#Signed Plugins#Kernel Security

Community Discussion

No community discussion yet for this question.

Full 1Z0-820 Practice