Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A company is implementing a new security policy that requires all network traffic between different departments within the internal network to be encrypted and authenticated. This is to prevent any internal snooping or tampering. Which protocol suite is best suited for securing communications specifically at the network layer (Layer 3)?

  1. ASecure Sockets Layer (SSL)
  2. BInternet Protocol Security (IPsec)
  3. CSecure Shell (SSH)
  4. DTransport Layer Security (TLS)
Show answer & explanation

Correct answer: B. Internet Protocol Security (IPsec)

IPsec is a suite of protocols that provides security services at the network layer (Layer 3) of the OSI model. It offers both authentication and encryption for IP packets, making it ideal for securing internal network traffic between different departments.

Why the other options are wrong

  • A. SSL is an older, deprecated version of TLS and also operates at the transport layer (Layer 4).
  • C. SSH operates at the application layer (Layer 7) and is used for secure remote access and file transfer.
  • D. TLS operates at the transport layer (Layer 4) and is primarily used for securing application traffic like HTTPS.

IPsec (Internet Protocol Security)

A suite of protocols that provides security services (authentication, integrity, confidentiality) at the IP layer of the network.

  • Operates at OSI Layer 3 (Network Layer).
  • Provides both encryption and authentication.
  • Commonly used for VPNs and securing internal network communications.
  • Consists of Authentication Header (AH) and Encapsulating Security Payload (ESP).

Memory trick: IPsec: Securing the 'road' (IP) itself, not just the 'cargo' (applications).

More Network Security questions