ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
A security architect is designing a network for a new branch office that will handle sensitive customer data. The design requires a mechanism to ensure that all traffic between the branch office and the main data center is encrypted and authenticated at the network layer, without requiring application-specific configurations. Which protocol suite is BEST suited for this requirement?
- AIPsec
- BSSH
- CHTTPS
- DSSL/TLS
Show answer & explanationAnswer & explanation
Correct answer: A. IPsec
IPsec operates at the network layer (Layer 3) and provides end-to-end encryption and authentication for IP packets, making it ideal for securing traffic between networks like a branch office and a data center without application-level changes. SSL/TLS and HTTPS operate at higher layers, while SSH is typically used for secure remote access.
Why the other options are wrong
- B. SSH is primarily used for secure remote command-line access and file transfer, not for general network-layer traffic encryption between sites.
- C. HTTPS uses SSL/TLS and operates at the application layer, securing web traffic, not all network traffic between locations.
- D. SSL/TLS operates at the transport layer and requires application-level integration, not network layer encryption for all traffic.
IPsec
A suite of protocols that provides security for Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.
- Operates at the network layer (Layer 3).
- Provides confidentiality, integrity, and authentication.
- Commonly used for VPNs and securing traffic between networks.
Memory trick: IPsec is the strong 'IP' for network-level protection.