DevNet Associate (DEVASC) v1.0Network FundamentalsHard
A cloud engineer is designing a secure connection between an on-premises data center and a cloud provider's virtual private cloud (VPC). The connection must provide data confidentiality and integrity over the public internet. Which network security technology is typically used to achieve this?
- ANAT
- BVPN
- CDHCP
- DARP
Show answer & explanationAnswer & explanation
Correct answer: B. VPN
A Virtual Private Network (VPN) creates a secure, encrypted tunnel over an unsecure network (like the internet), ensuring data confidentiality and integrity between the two endpoints, which is perfect for connecting a data center to a cloud VPC.
Why the other options are wrong
- A. NAT (Network Address Translation) translates IP addresses and provides some security by hiding internal addresses but does not encrypt data.
- C. DHCP (Dynamic Host Configuration Protocol) assigns IP addresses and has no security tunneling capabilities.
- D. ARP (Address Resolution Protocol) resolves IP addresses to MAC addresses within a local segment and offers no security for data in transit.
VPN (Virtual Private Network)
A VPN extends a private network across a public network, enabling users to send and receive data across shared or public networks as if their computing devices were directly connected to the private network.
- Creates an encrypted tunnel for data transmission.
- Provides confidentiality, integrity, and authentication.
- Commonly used for remote access and site-to-site connectivity.
Memory trick: Secure your Network: 'Protect, Encrypt, Authenticate'