Soru

Zorluk: OrtaVirtual Private Networks and Remote Access Security

A network security analyst is reviewing a remote access VPN architecture that combines Layer 2 Tunneling Protocol (L2TP) with IPsec alongside a centralized AAA server infrastructure. Which of the following statements correctly describe the technical protocol characteristics and operational requirements of this solution? (Select TWO.)

  1. L2TP handles data link layer encapsulation for remote connections but does not inherently provide payload confidentiality, requiring IPsec for encryption.Cevap
  2. IPsec Internet Key Exchange (IKE) phase 1 negotiations use UDP port 500 to establish the initial Security Association (SA) between endpoints.Cevap
  3. C
    IPsec Authentication Header (AH) functions at the Application layer (Layer 7) to provide robust symmetric payload encryption across untrusted networks.
  4. D
    RADIUS encrypts the entire packet payload during transmission, while TACACS+ encrypts only the password field of the authentication request.

Cevap

The correct statements are that L2TP provides data link layer encapsulation while relying on IPsec for encryption, and that IPsec IKE phase 1 negotiations communicate via UDP port 500.
L2TP provides frame tunneling at Layer 2 but does not specify cryptographic protection. Consequently, L2TP relies on IPsec to provide confidentiality and integrity. Additionally, IPsec uses IKE on UDP port 500 to establish Security Associations and exchange keys during phase 1 setup.

Adım Adım Çözüm

1
Evaluate the role and security capabilities of L2TP in a combined remote access VPN.
Identify that L2TP operates at Layer 2 to encapsulate PPP frames but lacks built-in encryption, requiring IPsec (specifically ESP) to secure transmitted data.
Understanding protocol layering reveals why L2TP and IPsec are frequently deployed together.
2
Verify the standard port and transport protocol used by IPsec IKE.
Confirm that IKE uses UDP port 500 for key exchange and SA negotiation in Phase 1.
Standard port identification is essential for configuring firewall rules for IPsec VPN tunnels.
3
Analyze distractors relating to OSI layer mapping and AAA encryption behavior.
Determine that IPsec AH operates at Layer 3 (without encryption) and that TACACS+ encrypts the entire packet body whereas RADIUS encrypts only the password.
Eliminates incorrect protocol claims.

Anahtar Kavram

L2TP/IPsec Protocol Integration and Centralized AAA AAA Characteristics
Bu soruyu puanla