Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network engineer is deploying a new site-to-site VPN tunnel between two branch offices using IPsec. The security policy requires that the data integrity of the packets is ensured, but confidentiality is not strictly necessary for all traffic types. Which IPsec component is primarily responsible for providing data integrity without necessarily encrypting the data payload?

  1. AAuthentication Header (AH)
  2. BSecurity Association (SA)
  3. CEncapsulating Security Payload (ESP)
  4. DInternet Key Exchange (IKE)
Show answer & explanation

Correct answer: A. Authentication Header (AH)

Authentication Header (AH) provides data integrity, data origin authentication, and anti-replay services. It does not provide confidentiality (encryption), which aligns with the requirement for integrity without strict confidentiality.

Why the other options are wrong

  • B. An SA is a logical connection that defines the security parameters, not a protocol for integrity itself.
  • C. ESP provides confidentiality and can also provide integrity, but its primary function is encryption.
  • D. IKE is used for key exchange and SA establishment, not direct data integrity.

IPsec Authentication Header (AH)

An IPsec protocol that provides connectionless data integrity, data origin authentication, and an anti-replay service.

  • Does not provide confidentiality (encryption).
  • Authenticates the entire IP packet (except mutable fields).
  • Identified by IP Protocol number 51.

Memory trick: IPsec has two main bodyguards: one for a full suit of armor, one for a stealth cloak.

More Security questions