CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A security architect is designing a secure communication channel between two globally distributed data centers. The primary requirements are strong encryption for data in transit, mutual authentication between the endpoints, and protection against replay attacks. The solution must operate at the network layer to encapsulate various higher-layer protocols. Which of the following protocols would be best suited for this scenario?

  1. ATLS (Transport Layer Security)
  2. BHTTPS (Hypertext Transfer Protocol Secure)
  3. CSSH (Secure Shell)
  4. DIPsec (Internet Protocol Security)
Show answer & explanation

Correct answer: D. IPsec (Internet Protocol Security)

IPsec operates at the network layer, providing strong encryption, authentication, and anti-replay services for IP packets. This aligns perfectly with the requirements for securing communication between globally distributed data centers at a foundational network level.

Why the other options are wrong

  • A. TLS operates at the transport layer and primarily secures application-level communication, not the entire network layer traffic.
  • B. HTTPS is an application-layer protocol that secures web traffic, which is too specific for the broad network-layer requirements of this scenario.
  • C. SSH is primarily used for secure remote access and command execution, not for general network-layer data center-to-data center communication.

IPsec (Internet Protocol Security)

A suite of protocols used to secure IP communications by authenticating and encrypting each IP packet of a communication session.

  • Operates at the network layer (Layer 3 of OSI model).
  • Provides data confidentiality, integrity, and authenticity.
  • Supports two modes: Transport mode (host-to-host) and Tunnel mode (network-to-network).

Memory trick: IPsec is the Internet's Private Security guard.

More Security Architecture questions