SSCP Systems Security Certified PractitionerNetwork and Communications SecurityHard
A company policy mandates that all data transmitted over the internal network must be encrypted, even between devices within the same subnet. The existing network infrastructure predominantly consists of managed switches that support various security features. Which of the following technologies would be most appropriate to implement this policy efficiently without requiring a full VPN tunnel for every internal communication?
- AMACsec (802.1AE)
- BIPsec Transport Mode
- CSSL/TLS VPN
- DPPTP
Show answer & explanationAnswer & explanation
Correct answer: A. MACsec (802.1AE)
MACsec (802.1AE) operates at Layer 2 (Data Link Layer) and provides hop-by-hop encryption for all traffic on a local network segment, ensuring confidentiality and integrity between devices on the same subnet without routing overhead or complex VPN configurations for every internal communication.
Why the other options are wrong
- B. IPsec Transport Mode encrypts the payload of an IP packet but requires higher-layer processing and is typically used for host-to-host or gateway-to-host VPNs, not ideal for blanket Layer 2 encryption within a subnet.
- C. SSL/TLS VPNs typically operate at Layer 3 or above and are designed for remote access or site-to-site connections, not for transparent, hop-by-hop encryption within a local subnet.
- D. PPTP (Point-to-Point Tunneling Protocol) is an older, insecure VPN protocol that operates at Layer 2 but lacks strong encryption and authentication, making it unsuitable for a policy requiring robust encryption.
MACsec (802.1AE)
A standard that defines connectionless data confidentiality and integrity for media access independent protocols.
- Operates at Layer 2 (Data Link Layer).
- Provides hop-by-hop encryption for Ethernet frames.
- Secures traffic within a local area network segment.
Memory trick: Layer 2 MACsec secures hops, Layer 3 IPsec secures packets, Layer 4+ TLS secures apps.