CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard
A server administrator is implementing a security policy that requires all communication between servers in a private network segment to be encrypted and authenticated to prevent man-in-the-middle attacks and ensure data integrity. Which protocol suite is specifically designed to provide these security services at the network layer?
- ASSL/TLS
- BIPsec
- CSSH
- DHTTPS
Show answer & explanationAnswer & explanation
Correct answer: B. IPsec
IPsec (Internet Protocol Security) is a suite of protocols that provides security for Internet Protocol (IP) communications by authenticating and encrypting each IP packet. It operates at the network layer, securing all traffic between two IPsec endpoints.
Why the other options are wrong
- A. SSL/TLS operates at the transport layer (or above) and secures specific application traffic, not all network layer communication.
- C. SSH (Secure Shell) is an application-layer protocol for secure remote access and file transfer, not for securing all network traffic.
- D. HTTPS uses SSL/TLS to secure web traffic at the application layer, not generic network layer communication.
IPsec
A suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.
- Operates at the network layer (Layer 3).
- Provides confidentiality, integrity, and authentication.
- Commonly used for VPNs.
Memory trick: IPsec adds a 'shield' to every IP packet.