PrepAway - Latest Free Exam Questions & Answers

which secure channel?

In a group VPN the members rekey with the server using the Unicast PUSH method. This rekey mechanism is protected by which secure channel?

PrepAway - Latest Free Exam Questions & Answers

A.
KEK

B.
IPSec SA

C.
TEK

D.
IKE SA

4 Comments on “which secure channel?

  1. hisham says:

    there is three type of rekey methods:

    pull methods: using IKE SA and no need for KEK

    unicast push methods:using KEK with Ack mechanism

    multicast push methods: KEK without Ack mechanism




    0



    0
  2. Sajid says:

    Answer: D (IKE SA)

    It’s true that Key Encryption Key (KEK) is used to encrypt rekey messages. But in the same time GDOI exchanges in Phase 2 must be protected by ISAKMP Phase 1 Sas. And GDOI groupkey – push exchange is one of the two types of GDOI exchanges: groupkey-pull and groupkey-push.




    0



    0

Leave a Reply