Huawei HCNP-Security-CISN (Huawei Certified Network Professional - Constructing Infrastructure of Security Network) H12-721 Question # 53 Topic 6 Discussion
H12-721 Exam Topic 6 Question 53 Discussion:
Question #: 53
Topic #: 6
What are the correct descriptions of IPSec and IKE below?
A.
IPSec has two negotiation modes to establish an SA. One is manual (manual) and the other is IKE (isakmp) auto-negotiation.
B.
IKE aggressive mode can choose to find the corresponding authentication key according to the negotiation initiator IP address or ID and finally complete the negotiation.
C.
NAT traversal function deletes the verification process of the UDP port number during the IKE negotiation process, and implements the discovery function of the NAT gateway device in the VPN tunnel. That is, if the NAT gateway device is found, it will be used in the subsequent IPSec data transmission. UDP encapsulation
D.
IKE security mechanisms include DH Diffie-Hellman exchange and key distribution, complete forward security and SHA1 encryption algorithms.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit