Study. uk . com
  1. Home
  2. All questions
  3. Question 278

CISSP study material · question 278 of 500

A packet arrives at an IPsec boundary and matches no rule requiring protection. Which three outcomes does the security policy database allow for traffic at that boundary? Choose three.

  1. The packet is queued until a security association can be negotiated.
  2. The packet is allowed to bypass IPsec protection.
  3. The packet is discarded.
  4. The packet is protected using IPsec security services.
Show the answer

Answer: B. The packet is allowed to bypass IPsec protection.
D. The packet is protected using IPsec security services.
C. The packet is discarded.

RFC 4301 has traffic at the IPsec boundary protected, discarded, or allowed to bypass IPsec protection, according to the applicable policy database entries.

Source: RFC 4301 (IETF) — RFC 4301 > 3.1 What IPsec Does

Challenge yourself on this topic → Study as cards