nerdexam
Cisco

300-440 · Question #51

Refer to the exhibit. An engineer establishes IPsec, internet-based, secure cloud connectivity between an on-premises Cisco IOS XE router and a native AWS endpoint. Which parameters were used to…

The correct answer is A. Encryption algorithm: AES-CBC-256. Encryption algorithm: The exhibit specifies "Encr: AES-CBC, keysize: 256," which means the encryption algorithm used is AES in Cipher Block Chaining mode with a 256-bit key (AES-CBC- Integrity algorithm: The line "Hash: SHA256" indicates that SHA256 is being used as the…

IPsec Cloud Connectivity

Question

Refer to the exhibit. An engineer establishes IPsec, internet-based, secure cloud connectivity between an on-premises Cisco IOS XE router and a native AWS endpoint. Which parameters were used to configure phase 1 of the IPsec VPN connection?

Exhibit

300-440 question #51 exhibit

Options

  • AEncryption algorithm: AES-CBC-256
  • BEncryption algorithm: AES-CBC-128
  • CEncryption algorithm: AES-CBC-128
  • DEncryption algorithm: AES-CBC-256

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    4% (1)
  • C
    4% (1)
  • D
    11% (3)

Explanation

Encryption algorithm: The exhibit specifies "Encr: AES-CBC, keysize: 256," which means the encryption algorithm used is AES in Cipher Block Chaining mode with a 256-bit key (AES-CBC- Integrity algorithm: The line "Hash: SHA256" indicates that SHA256 is being used as the integrity algorithm to ensure data authenticity and integrity during IKEv2 phase 1 negotiations. Diffie-Hellman group: The exhibit shows "DH Grp:16," confirming that Diffie-Hellman group 16 is used for key exchange, which provides strong cryptographic security during the IKEv2 phase 1 negotiation process.

Topics

#IPsec phase 1#IKE parameters#AES-CBC-256#AWS VPN

Community Discussion

No community discussion yet for this question.

Full 300-440 Practice