Cisco CCNA (200-301)Security FundamentalsHard
A network administrator is designing an IPsec VPN and must choose a security protocol that provides both encryption and authentication of the packet payload, as opposed to a protocol that only provides authentication and integrity without encryption. Which IPsec protocol should be selected?
- AAuthentication Header (AH)
- BGeneric Routing Encapsulation (GRE)
- CEncapsulating Security Payload (ESP)
- DInternet Key Exchange (IKE)
Show answer & explanationAnswer & explanation
Correct answer: C. Encapsulating Security Payload (ESP)
ESP (Encapsulating Security Payload, IP protocol 50) provides both confidentiality (encryption) and authentication/integrity of the IP packet payload. AH (protocol 51) provides only authentication and integrity, with no encryption. Because the requirement includes encryption, ESP is the correct choice.
Why the other options are wrong
- A. AH provides authentication and integrity but does not encrypt the payload.
- B. GRE is a tunneling protocol without built-in encryption or authentication.
- D. IKE is used to negotiate and establish the security association, not to protect data itself.
ESP vs AH
ESP (protocol 50) encrypts and authenticates IPsec payloads, while AH (protocol 51) only authenticates and provides integrity without encryption.
- ESP = confidentiality + integrity + authentication
- AH = integrity + authentication only, no encryption
- IKE negotiates keys/SAs but doesn't protect traffic itself
Memory trick: ESP Encrypts, AH just Authenticates.