exam questions

Exam 312-50v11 All Questions

View all questions & answers for the 312-50v11 exam

Exam 312-50v11 topic 1 question 62 discussion

Actual exam question from ECCouncil's 312-50v11
Question #: 62
Topic #: 1
[All 312-50v11 Questions]

Which mode of IPSec should you use to assure security and confidentiality of data within the same LAN?

  • A. ESP transport mode
  • B. ESP confidential
  • C. AH permiscuous
  • D. AH Tunnel mode
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bot001
Highly Voted 2 years, 2 months ago
ESP transport mode should be used to ensure the integrity and confidentiality of data that is exchanged within the same LAN. What is transport mode and tunnel mode in IPsec? In transport mode, the IP addresses in the outer header are used to determine the IPsec policy that will be applied to the packet. In tunnel mode, two IP headers are sent.
upvoted 27 times
...
americaman80
Highly Voted 2 years, 6 months ago
Correct
upvoted 6 times
...
juliosc
Most Recent 9 months ago
Authentication Header (AH): It offers integrity and data origin authentication, with optional anti-replay features. Encapsulating Security Payload (ESP): It offers all the services offered by AH as well as confidentiality.
upvoted 1 times
...
Daniel8660
1 year ago
Selected Answer: A
Transport Mode - In the transport mode (also ESP), IPsec encrypts only the payload of the IP packet, leaving the header untouched. It authenticates two connected computers and provides the option of encrypting data transfer. (P.1464/1448)
upvoted 4 times
...
dinonino
1 year, 1 month ago
In the tunnel mode (also AH), the IPsec encrypts both the payload and header. Hence, in the tunnel mode has higher security than the transport mode. After receiving the data, the IPsec-compliant device performs decryption. The tunnel model is used to create VPNs over the Internet for network-to-network communication (e.g., between routers and link sites), host-to-network communication (e.g., remote user access), and host-to-host communication (e.g., private chat). It is compatible with NAT and supports NAT traversal. In the tunnel mode, the system encrypts entire IP packets (payload and IP header) and encapsulates the encrypted packets into a new IP packet with a new header. In this mode, ESP encrypts and optionally authenticates entire inner IP packets, whereas AH authenticates entire inner IP packets and selected fields of outer IP headers. The tunnel mode is usually useful between two gateways or between a host and gateway.
upvoted 1 times
dinonino
1 year, 1 month ago
In the transport mode (also ESP), IPsec encrypts only the payload of the IP packet, leaving the header untouched. It authenticates two connected computers and provides the option of encrypting data transfer. It is compatible with network address translation (NAT); therefore, it can be used to provide VPN services for networks utilizing NAT. Figure
upvoted 1 times
dinonino
1 year, 1 month ago
AH transport mode ESP transport mode ESP tunnel mode AH tunnel mode Answer B is correct. ESP transport mode should be used to ensure the integrity and confidentiality of data that is exchanged within the same LAN. AH transport would only ensure the integrity of the LAN data, not the confidentiality; therefore, answer A is incorrect. ESP tunnel mode should be used to secure the integrity and confidentiality of data between networks and not within a network; therefore, answer C is incorrect. AH tunnel mode should be used to secure the integrity of data between networks and not within a network; therefore, answer D is incorrect.
upvoted 2 times
...
...
Sxn
10 months, 3 weeks ago
Great explanation. However, As per Matt Walker's book, p.404 "Tunnel mode, however, encrypts the whole thing, encapsulating the entire original packet in a new IPSec Schell. This makes it INCOMPATIBLE with NAT."
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago