300-420 exam dumps

300-420 practice question 199 of 323

Designing Cisco Enterprise Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-420 Question 199

Select 2

A network engineer is designing a site-to-site VPN between two branch offices using IPsec. One key requirement is that the data must be encrypted and authenticated during transit, while also ensuring that the VPN can withstand replay attacks. Which combination of IPsec protocol and feature should the engineer include in the design?

  1. A

    Use Encapsulating Security Payload (ESP) for encryption and authentication.

  2. B

    Use Authentication Header (AH) for encryption and authentication.

  3. C

    Enable anti-replay protection to prevent replay attacks.

  4. D

    Disable anti-replay protection to improve performance.

  5. E

    Use ESP in transport mode for network layer encryption.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the requirements of encryption, authentication, and protection against replay attacks, the network engineer should use ESP with anti-replay protection enabled. ESP provides both encryption and authentication, while anti-replay protection ensures that packets cannot be intercepted and replayed by an attacker. AH is insufficient because it does not provide encryption, and disabling anti-replay protection would compromise security.

  • A. Correct.

    Encapsulating Security Payload (ESP) provides both encryption and authentication for IPsec traffic, making it suitable for securely transmitting data.

  • B. Incorrect.

    Authentication Header (AH) does not provide encryption; it only provides authentication and integrity, which does not meet the design requirement for encryption.

  • C. Correct.

    Anti-replay protection is a vital feature of IPsec that prevents attackers from capturing and replaying packets, ensuring the integrity of the VPN connection.

  • D. Incorrect.

    Disabling anti-replay protection may improve performance but compromises security, which violates the design requirement to prevent replay attacks.

  • E. Incorrect.

    ESP in transport mode encrypts only the payload and leaves the IP header unencrypted, which is generally less secure and not ideal for site-to-site VPNs.

Timed practice exam

Take a 300-420 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam