nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #123

Which of these statements about the security implications of IPv6 is NOT true? ()

The correct answer is B. IPv6's NAT implementation is insecure. The statement that 'IPv6's NAT implementation is insecure' is NOT true because IPv6 was explicitly designed to eliminate the need for Network Address Translation (NAT). IPv6's massive address space means every device can have a globally unique address, making NAT unnecessary…

Network Security Concepts

Question

Which of these statements about the security implications of IPv6 is NOT true? ()

Options

  • ARules based on static IPv6 addresses may not work
  • BIPv6's NAT implementation is insecure
  • CIPv6 traffic may bypass existing security controls
  • DIPv6 reputation services may not be mature and useful

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    86% (36)
  • C
    7% (3)
  • D
    2% (1)

Explanation

The statement that 'IPv6's NAT implementation is insecure' is NOT true because IPv6 was explicitly designed to eliminate the need for Network Address Translation (NAT). IPv6's massive address space means every device can have a globally unique address, making NAT unnecessary. There is no standard, widely deployed NAT implementation in IPv6. The other statements are all valid IPv6 security concerns: static-address-based ACL rules may fail due to IPv6 privacy extensions (A), dual-stack hosts can bypass IPv4-only controls (C), and IPv6 threat intelligence feeds are less mature than IPv4 ones (D).

Topics

#IPv6 Security#Network Security#NAT#IPv6 Addressing

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice