4A0-107 · Question #52
Which of the following are trusted boundaries, by default? (Choose two)
The correct answer is C. A network port D. AVPRN SAP. In Nokia SR OS, network ports (C) are trusted by default because they connect to other network elements within the same administrative domain - peer routers and switches are assumed to forward correctly marked traffic. VPRN SAPs (D) are also trusted by default, as Virtual…
Question
Which of the following are trusted boundaries, by default? (Choose two)
Options
- AAn IES SAP
- BA VPLS SAP
- CA network port
- DAVPRN SAP
- EAn access port
How the community answered
(44 responses)- A9% (4)
- B2% (1)
- C86% (38)
- E2% (1)
Explanation
In Nokia SR OS, network ports (C) are trusted by default because they connect to other network elements within the same administrative domain - peer routers and switches are assumed to forward correctly marked traffic. VPRN SAPs (D) are also trusted by default, as Virtual Private Routed Network service access points operate at Layer 3 and are associated with authenticated, administratively controlled routing contexts.
IES SAPs (A) and VPLS SAPs (B) are untrusted by default because they are customer-facing service endpoints - IES (Internet Enhanced Service) and VPLS (Virtual Private LAN Service) both present Layer 3/Layer 2 interfaces to external or customer equipment whose QoS markings cannot be implicitly trusted. Access ports (E) are similarly untrusted by default, as they face end-user devices or customer premises equipment.
Memory tip: Think "network = internal = trusted, access/customer-facing = external = untrusted." The exception to keep in mind is that among SAP types, VPRN SAPs buck the trend - their routed, L3-VPN nature earns them default trust alongside network ports. On the exam, if you remember "network ports + VPRN SAPs = trusted by default," you cover both correct answers.
Topics
Community Discussion
No community discussion yet for this question.