350-701 · Question #298
An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK and sequence. Which protocol accomplishes this goal?
The correct answer is D. ESP. ESP (Encapsulating Security Payload) is the IPsec protocol component that offers reliability through anti-replay protection, which involves the use of sequence numbers to prevent duplicate packets.
Question
An engineer is configuring IPsec VPN and needs an authentication protocol that is reliable and supports ACK and sequence. Which protocol accomplishes this goal?
Exhibit
Options
- AAES-192
- BIKEv1
- CAES-256
- DESP
How the community answered
(48 responses)- A4% (2)
- B2% (1)
- C2% (1)
- D92% (44)
Why each option
ESP (Encapsulating Security Payload) is the IPsec protocol component that offers reliability through anti-replay protection, which involves the use of sequence numbers to prevent duplicate packets.
AES-192 is an encryption algorithm that provides confidentiality, not a protocol for authentication, ACKs, or sequence numbers.
IKEv1 is a key exchange protocol used for establishing and managing IPsec Security Associations, not for directly authenticating data packets with ACK and sequence numbers.
AES-256 is an encryption algorithm that provides confidentiality, not a protocol for authentication, ACKs, or sequence numbers.
ESP provides data origin authentication, data integrity, and confidentiality, and includes anti-replay protection which relies on sequence numbers to detect and drop duplicate or replayed packets, thereby ensuring a form of reliability in the data plane.
Concept tested: IPsec ESP features
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpn/configuration/xe-16-9/sec-conn-vpn-xe-16-9-book/sec-conn-vpn-intro.html
Topics
Community Discussion
No community discussion yet for this question.
