ExamRange

CND (312-38) Network Defense Simulation

Enhance your understanding of secure remote access architectures. This simulation focuses on evaluating VPN protocols to ensure confidentiality, integrity, and authenticity across untrusted networks.

Network Scenario

Your organization is establishing a new branch office and requires a site-to-site VPN connection over the public internet to connect the branch to the corporate Headquarters (HQ). The Chief Information Security Officer (CISO) has mandated that the new connection must not use proprietary protocols and must provide native, robust encryption and data integrity to defend against packet sniffing and Man-in-the-Middle (MITM) attacks.

You are reviewing the current VPN gateway capabilities to select the appropriate protocol standard.

Traffic & Logs

[FW-HQ-01] VPN Configuration Requirements Review
------------------------------------------------
> Task: Branch_02 Site-to-Site Tunnel
> Requirement_1: Standard-based (IETF compliant)
> Requirement_2: Network Layer (Layer 3) encapsulation
> Requirement_3: Must support AES-256 for confidentiality
> Requirement_4: Must support SHA-256 for integrity/authentication
> Status: Awaiting protocol selection.

Question

Which of the following is a standard-based protocol that provides the highest level of VPN security?