300-415 · Question #13
Which two mechanisms are used to guarantee the integrity of data packets in the Cisco SD-WAN architecture data plane? (Choose two.)
The correct answer is C. authentication headers D. encapsulation security payload. In the Cisco SD-WAN data plane, Authentication Headers (AH) and Encapsulation Security Payload (ESP) are the two IPsec mechanisms that guarantee packet integrity.
Question
Options
- Acertificates
- Btransport locations
- Cauthentication headers
- Dencapsulation security payload
- ETPM chip
How the community answered
(47 responses)- A2% (1)
- B2% (1)
- C89% (42)
- E6% (3)
Why each option
In the Cisco SD-WAN data plane, Authentication Headers (AH) and Encapsulation Security Payload (ESP) are the two IPsec mechanisms that guarantee packet integrity.
Certificates are used in the Cisco SD-WAN control plane for device authentication and identity verification, not for guaranteeing data plane packet integrity.
Transport locations (TLOCs) are logical identifiers representing a WAN Edge's transport attachment points and are not security mechanisms for ensuring packet integrity.
Authentication Headers (AH) provide data origin authentication and integrity verification for IP packets by computing an HMAC over the packet contents, ensuring packets have not been tampered with in transit.
Encapsulation Security Payload (ESP) provides both confidentiality through encryption and data integrity through authentication, making it a core mechanism for protecting SD-WAN data plane traffic in IPsec tunnels.
A TPM chip is a hardware security module used for secure key storage and platform integrity attestation during boot, not a mechanism that operates in the data plane to guarantee packet integrity.
Concept tested: Cisco SD-WAN data plane IPsec integrity mechanisms
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/security-overview.html
Topics
Community Discussion
No community discussion yet for this question.