exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 330 discussion

Actual exam question from Cisco's 300-410
Question #: 330
Topic #: 1
[All 300-410 Questions]

Which of the following is true regarding IPsec Pre-fragmentation (Look-Ahead Fragmentation)? (Choose two.)

  • A. Operates in tunnel mode only
  • B. Operates in transport mode only
  • C. Is used to help in the overall IPsec throughput since the end host is able to avoid packet reassembly after packet decryption.
  • D. Is not dependent on the MTU of the physical interface used for IPsec.
  • E. Does not support Path MTU Discovery
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tubirubs
9 months, 3 weeks ago
Selected Answer: CE
C. Is used to help in the overall IPsec throughput since the end host is able to avoid packet reassembly after packet decryption. Correct: Pre-fragmentation (or Look-Ahead Fragmentation) helps improve IPsec throughput by ensuring that packets are fragmented before they are encrypted. This reduces the need for reassembly at the end host after decryption, leading to better performance and efficiency. E. Does not support Path MTU Discovery Correct: IPsec pre-fragmentation does not support Path MTU Discovery (PMTUD). PMTUD is used to discover the maximum packet size that can be transmitted without fragmentation, but pre-fragmentation is a different approach that works around the MTU issue by fragmenting packets before encryption.
upvoted 2 times
...
[Removed]
10 months, 2 weeks ago
Selected Answer: AC
A & C are correct
upvoted 1 times
...
alex711
1 year, 9 months ago
Selected Answer: AC
A, C is correct. https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/www.cisco.com/content/en/us/td/docs/interfaces_modules/shared_port_adapters/configuration/6500series/sipspasw/76cfvpnb.html.xml
upvoted 1 times
...
mitosenoriko
2 years, 5 months ago
A and C is correct I checked cisco documents.
upvoted 1 times
...
Zizu007
2 years, 5 months ago
Selected Answer: AC
Correct! https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dplane/configuration/xe-16-10/sec-ipsec-data-plane-xe-16-10-book/sec-pre-frag-vpns.html Restrictions for Pre-Fragmentation for IPsec VPNs Take the following information into consideration before this feature is configured: Pre-fragmentation for IPsec VPNs operates in IPsec tunnel mode and IPsec tunnel mode with GRE, but not with IPsec transport mode. Pre-fragmentation for IPsec VPNs configured on the decrypting router in a unidirectional traffic scenario does not improve the performance or change the behavior of either of the peers. Pre-fragmentation for IPsec VPNs occurs before the transform is applied if compression is turned on for outgoing packets. Pre-fragmentation for IPsec VPNs functionality depends on the egress interface crypto ipsec df-bit configuration and the incoming packet “do not fragment” (DF) bit state. See the table below.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...