300-410 exam dumps

300-410 practice question 186 of 293

Implementing Cisco Enterprise Advanced Routing and Services. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-410 Question 186

Single answer

An enterprise network administrator is configuring an IPsec VPN between two branch offices. The administrator wants to ensure data integrity and authentication during the IKE Phase 2 negotiation. Which configuration parameter should be included to achieve this?

  1. A

    Authentication Header (AH)

  2. B

    Encapsulation Security Payload (ESP) with null encryption

  3. C

    Diffie-Hellman Group 1

  4. D

    Pre-shared Key

Show answer and explanation

Correct answer: B

Explanation

During IKE Phase 2, Encapsulation Security Payload (ESP) is used to provide data integrity, authentication, and optionally encryption. By using ESP with null encryption, the administrator can ensure that data is authenticated and its integrity is verified without encrypting the payload. This approach is useful in scenarios where encryption is not required but integrity and authentication are critical.

  • A. Incorrect.

    Authentication Header (AH) provides authentication and integrity but does not support encryption. While it ensures data integrity, it is not commonly used in IKE Phase 2 because ESP can provide both integrity and encryption.

  • B. Correct.

    Encapsulation Security Payload (ESP) with null encryption ensures data integrity and authentication without encrypting the payload. This option is correct because ESP can provide integrity and authentication using mechanisms such as HMAC.

  • C. Incorrect.

    Diffie-Hellman Group 1 is used for key exchange during IKE Phase 1 and does not directly impact data integrity and authentication in IKE Phase 2.

  • D. Incorrect.

    Pre-shared Key is used for authenticating peers during IKE Phase 1 and is not related to ensuring data integrity and authentication during IKE Phase 2.

Timed practice exam

Take a 300-410 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam