Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam JN0-635 topic 1 question 17 discussion

Actual exam question from Juniper's JN0-635
Question #: 17
Topic #: 1
[All JN0-635 Questions]

Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)

  • A. Data is transmitted across the link in plaintext
  • B. The link is not protected against man-in-the-middle attacks
  • C. The link is protected against man-in-the-middle attacks
  • D. Data is transmitted across the link in cyphertext
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
psalm
2 years, 4 months ago
B&D because replay protection is off Replay protection is especially useful for fighting man-in-the-middle attacks. A packet that is replayed by a man-in-the-middle attacker on the Ethernet link will arrive on the receiving link out of sequence, so replay protection helps ensure the replayed packet is dropped instead of forwarded through the network. https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/task/macsec.html
upvoted 3 times
greeklover84
1 year, 2 months ago
as soon as there is encryption you are protected against the MiTM or am I wrong ? I think C and D
upvoted 2 times
...
...
nickanme
2 years, 5 months ago
https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-38d.pdf GCM-AES-128 does not inherently prevent an adversary from intercepting the output of an invocation of authenticated encryption and “replaying” it for authenticated decryption at a later time. The fact that MACsec "is capable of identifying and preventing most security threats, including denial of service, intrusion, man-in-the-middle(...)." is not telling us anything about this specific config since we can configure MACsec without encryption - we still have to verify provided output. "Reply protection: off" "Encryption: on" so I guess: The link is not protected against man-in-the-middle attacks Data is transmitted across the link in cyphertext Is correct.
upvoted 3 times
...
Sateles
2 years, 9 months ago
C & D. "(...)is capable of identifying and preventing most security threats, including denial of service, intrusion, man-in-the-middle(...). https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/task/macsec.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...