exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 662 discussion

Actual exam question from CompTIA's SY0-601
Question #: 662
Topic #: 1
[All SY0-601 Questions]

A network administrator would like to configure a site-to-site VPN utilizing IPSec. The administrator wants the tunnel to be established with data integrity, encryption, authentication, and anti-replay functions. Which of the following should the administrator use when configuring the VPN?

  • A. AH
  • B. EDR
  • C. ESP
  • D. DNSSEC
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
touisuzuki
Highly Voted 1 year, 9 months ago
Selected Answer: C
A. AH (Authentication Header) provides authentication and data integrity but does not offer encryption or anti-replay protection. It does not encrypt the payload. B. EDR (Endpoint Detection and Response) is a security technology used for detecting and responding to advanced threats and breaches on endpoints (computers and servers). It's not related to configuring VPNs. C. ESP (Encapsulating Security Payload) is the correct choice for a site-to-site VPN when you need encryption, authentication, data integrity, and anti-replay protection. D. DNSSEC (Domain Name System Security Extensions) is used to add security to the DNS by providing authentication and data integrity for DNS data. It's not directly related to configuring VPNs with the specified requirements.
upvoted 29 times
...
fercho2023
Highly Voted 1 year, 8 months ago
Here are my Two Cents: VPN works on Layer 3. The only choice that runs on Layer 3 is Option C. ESP.
upvoted 11 times
...
david124
Most Recent 1 year, 5 months ago
I too picked ESP but im conflicted about the ani-replay requirement. I know AH provides ani-replay not ESP. right?
upvoted 1 times
MortG7
1 year, 5 months ago
Answer is C Advantages of ESP: Below listed are the advantages of Encapsulating Security Payload: Encrypting data to provide security Maintaining a secure gateway for data/ message transmission Properly authenticating the origin of data Providing needed data integrity Maintaining data confidentiality Helping with antireplay service using authentication header
upvoted 2 times
...
...
kong345
1 year, 7 months ago
Selected Answer: C
for sure C
upvoted 1 times
...
sujon_london
1 year, 9 months ago
Selected Answer: C
ESP is the Encapsulating Security Payload protocol in IPSec. It provides data confidentiality, connectionless data integrity, data origin authentication, an anti-replay service (a form of partial sequence integrity), and limited traffic-flow confidentiality.
upvoted 2 times
...
LeonardSnart
1 year, 10 months ago
Selected Answer: C
IPsec includes Encapsulating Security Payload (ESP) to encrypt the data and provide confidentiality. ESP includes AH so it provides confidentiality, authentication, and integrity. -Security+ SY0-601 Get Certified Get Ahead by Darril Gibson
upvoted 4 times
...
Kriss76
1 year, 10 months ago
C is correct: Encapsulating Security Payload (ESP) is a member of the Internet Protocol Security (IPsec) set of protocols that encrypt and authenticate the packets of data between computers using a Virtual Private Network (VPN). The focus and layer on which ESP operates makes it possible for VPNs to function securely.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...