Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityHard
A large enterprise is migrating a critical financial application to a public cloud environment. The security team is concerned about ensuring secure communication between the on-premises data center and the cloud-hosted application, as well as between different virtual machines within the cloud that host parts of the application. They require a suite of protocols that provide authentication, integrity, and confidentiality for IP communications. Which protocol suite is best suited for this task?
- ASSL/TLS
- BIPsec
- CSNMP
- DSSH
Show answer & explanationAnswer & explanation
Correct answer: B. IPsec
IPsec (Internet Protocol Security) is a suite of protocols that provides cryptographic protection for IP packets, offering authentication, integrity, and confidentiality, making it ideal for securing communication at the network layer between hosts or networks.
Why the other options are wrong
- A. SSL/TLS provides secure communication at the transport layer, primarily for applications like web browsers, not typically for entire network-level communication between VMs or sites.
- C. SNMP is used for network device management and monitoring, with some security features, but not for securing general data communications.
- D. SSH is primarily used for secure remote command-line access or file transfers, not for general network-level communication security for applications.
IPsec
A suite of protocols that provides cryptographic security for IP communications at the network layer (Layer 3).
- Offers authentication, integrity, and confidentiality.
- Used for Virtual Private Networks (VPNs) and securing host-to-host or network-to-network communication.
- Operates in two modes: Transport mode (host-to-host) and Tunnel mode (network-to-network).
Memory trick: IPsec: Securing IP packets, from network to network.