CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard
An organization is implementing a security policy that requires all communication between internal servers and external cloud services to be encrypted and authenticated. Which of the following protocols is best suited for establishing a secure, encrypted tunnel for this purpose?
- AFTP
- BIPsec
- CSSH
- DHTTP
Show answer & explanationAnswer & explanation
Correct answer: B. IPsec
IPsec (Internet Protocol Security) is a suite of protocols that provides cryptographic security for IP networks. It can be used to create secure, encrypted tunnels (VPNs) between two endpoints, authenticating and encrypting all traffic at the network layer, making it ideal for securing server-to-cloud communication.
Why the other options are wrong
- A. FTP (File Transfer Protocol) is inherently insecure and does not provide encryption or authentication for general communication.
- C. SSH (Secure Shell) provides a secure channel over an unsecured network for remote command execution and tunneling, but IPsec is designed for broader, network-layer VPNs.
- D. HTTP (Hypertext Transfer Protocol) is unencrypted; HTTPS (HTTP Secure) uses TLS/SSL but is application-layer, not a general tunnel protocol.
IPsec (Internet Protocol Security)
A suite of protocols that provides cryptographic security, including authentication and encryption, for communication over an Internet Protocol (IP) network.
- Operates at the network layer (Layer 3).
- Used to create secure VPN tunnels.
- Provides confidentiality, integrity, and authenticity.
Memory trick: IPsec secures the entire IP packet, not just the application.