ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

A security architect is designing a new network for a global enterprise. The design must ensure secure communication between geographically dispersed sites over untrusted networks, provide data confidentiality and integrity, and authenticate communicating parties. Which of the following technologies is best suited to meet these requirements?

  1. AVirtual Local Area Network (VLAN)
  2. BDomain Name System Security Extensions (DNSSEC)
  3. CNetwork Address Translation (NAT)
  4. DInternet Protocol Security (IPsec)
Show answer & explanation

Correct answer: D. Internet Protocol Security (IPsec)

IPsec provides a robust framework for securing IP communications by encrypting and authenticating IP packets. It is ideal for site-to-site VPNs, ensuring confidentiality, integrity, and authentication over public networks.

Why the other options are wrong

  • A. VLANs segment networks at Layer 2 but do not inherently provide encryption or secure communication over untrusted networks.
  • B. DNSSEC secures the DNS resolution process against spoofing but does not secure the data communication itself.
  • C. NAT translates IP addresses, primarily for conservation and hiding internal topology, but offers no security for data in transit.

IPsec

A suite of protocols used to secure IP communications by providing authentication, integrity, and confidentiality services.

  • Operates at the network layer (Layer 3) of the OSI model.
  • Commonly used for Virtual Private Networks (VPNs).
  • Includes Authentication Header (AH) and Encapsulating Security Payload (ESP) protocols.

Memory trick: IPsec is the 'Secure' way to 'Connect' 'Packets'.

More Communication and Network Security questions