nerdexam
Cisco

350-501 · Question #212

Refer lo the exhibit. An engineer working for private Service Provider with employee id: 3948:11:613 is configuring the BGPsec framework. Which two conditions must the engineer take into account?…

The correct answer is B. The BGPsec framework secures the AS path. C. In BGPsec. all route advertisements are given an expiry time by the originator of the route. BGPsec is an extension to BGP designed to provide cryptographic security for BGP route advertisements. Option B is correct because BGPsec's primary purpose is to secure the AS path attribute by using digital signatures, preventing AS path manipulation and route hijacking…

Networking

Question

Refer lo the exhibit. An engineer working for private Service Provider with employee id:

3948:11:613 is configuring the BGPsec framework. Which two conditions must the engineer take into account? (Choose two.)

Exhibit

350-501 question #212 exhibit

Options

  • ABGPsec uses iPsec tunnel for security.
  • BThe BGPsec framework secures the AS path.
  • CIn BGPsec. all route advertisements are given an expiry time by the originator of the route.
  • DPrivate keys are pan of the router key pair used to sign route updates.
  • EIn BGPsec, route advertisements are not given an expiration time by the originator of the route.

How the community answered

(45 responses)
  • A
    13% (6)
  • B
    78% (35)
  • D
    4% (2)
  • E
    4% (2)

Explanation

BGPsec is an extension to BGP designed to provide cryptographic security for BGP route advertisements. Option B is correct because BGPsec's primary purpose is to secure the AS path attribute by using digital signatures, preventing AS path manipulation and route hijacking. Option C is correct because in the BGPsec framework, route advertisements include validity periods or expiry timestamps assigned by the originating router, ensuring that stale or replayed route updates can be detected and rejected. Option A is incorrect because BGPsec uses its own digital signature mechanism, not IPsec tunnels. Option D is incorrect because public keys (not private keys alone) are distributed via RPKI; private keys are kept secret and used to sign but are not 'part of' route updates shared externally. Option E contradicts the correct behavior described in C.

Topics

#BGPsec#AS Path Validation#Digital Signatures#Route Security

Community Discussion

No community discussion yet for this question.

Full 350-501 Practice