CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A security architect is designing a secure communication channel for two geographically dispersed data centers. The goal is to ensure confidentiality, integrity, and authenticity of data in transit over an untrusted public network. Which protocol is best suited for establishing a secure tunnel between these two data centers?

  1. ASSH
  2. BHTTPS
  3. CIPsec
  4. DSSL/TLS
Show answer & explanation

Correct answer: C. IPsec

IPsec is the industry standard protocol suite used to secure IP communications by providing authentication, integrity, and confidentiality, making it ideal for site-to-site VPNs between data centers.

Why the other options are wrong

  • A. SSH is primarily used for secure remote access to individual hosts, not for securing traffic between entire networks.
  • B. HTTPS uses SSL/TLS and is specific to securing web traffic, not a general-purpose network tunneling protocol.
  • D. SSL/TLS is primarily used for securing application-layer protocols like web traffic, not typically for site-to-site network tunnels.

IPsec (Internet Protocol Security)

A suite of protocols used to secure IP communications by authenticating and encrypting each IP packet of a communication session.

  • Operates at the network layer (Layer 3).
  • Provides confidentiality, integrity, and authenticity.
  • Commonly used for VPNs (Virtual Private Networks).

Memory trick: IPsec secures the 'IP highway' between your data centers.

More Security Architecture questions