ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

A security architect is designing a network for a new branch office that will handle sensitive customer data. The design requires a mechanism to ensure that all traffic between the branch office and the main data center is encrypted and authenticated at the network layer, without requiring application-specific configurations. Which protocol suite is BEST suited for this requirement?

  1. AIPsec
  2. BSSH
  3. CHTTPS
  4. DSSL/TLS
Show answer & explanation

Correct answer: A. IPsec

IPsec operates at the network layer (Layer 3) and provides end-to-end encryption and authentication for IP packets, making it ideal for securing traffic between networks like a branch office and a data center without application-level changes. SSL/TLS and HTTPS operate at higher layers, while SSH is typically used for secure remote access.

Why the other options are wrong

  • B. SSH is primarily used for secure remote command-line access and file transfer, not for general network-layer traffic encryption between sites.
  • C. HTTPS uses SSL/TLS and operates at the application layer, securing web traffic, not all network traffic between locations.
  • D. SSL/TLS operates at the transport layer and requires application-level integration, not network layer encryption for all traffic.

IPsec

A suite of protocols that provides security for Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.

  • Operates at the network layer (Layer 3).
  • Provides confidentiality, integrity, and authentication.
  • Commonly used for VPNs and securing traffic between networks.

Memory trick: IPsec is the strong 'IP' for network-level protection.

More Communication and Network Security questions