JN0-231 Exam QuestionsBrowse all questions from this exam

JN0-231 Exam - Question 57


Which two statements are correct about IPsec security associations? (Choose two.)

Show Answer
Correct Answer: BD

IPsec security associations are unidirectional, meaning that each direction (inbound and outbound) has its own separate security association. These security associations are established during IKE Phase 2 negotiations. IKE Phase 1 is used to establish a secure channel between the two endpoints, but the actual IPsec security associations are set up in Phase 2.

Discussion

7 comments
Sign in to comment
RbrahmiOptions: BD
Feb 27, 2023

The correct answer is BD

4lex109Options: BD
Mar 13, 2023

The correct answer is BD

achonOptions: BD
May 2, 2023

unidirection and phase 2

deeqadri79Options: AC
Oct 20, 2023

A & C are correct IKE occurs over two phases. In the first phase, it negotiates security attributes and establishes shared secrets to form the bidirectional IKE SA. In the second phase, inbound and outbound IPsec SAs are established. The IKE SA secures the exchanges in the second phase. IKE also generates keying material, provides Perfect Forward Secrecy, and exchanges identities.

Engg_flintOptions: AD
Nov 4, 2023

A & D looks correct

66dc178Options: BD
Jan 28, 2024

A. While it might seem that IPsec SAs are bidirectional because they facilitate two-way communication, technically, each SA is unidirectional. Two SAs (inbound and outbound) are used to achieve bidirectional communication. C. IKE Phase 1 is responsible for setting up a secure, authenticated channel (the IKE SA) but does not establish the IPsec SAs themselves. Those are established in IKE Phase 2.

westh4m1234Options: BD
Mar 6, 2024

I agree with 66dc178 each SA is unidirectional that equal one bidirectional communication in a nutshell answer is BD for me and IKE is completely bidirectional.