exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 2 discussion

Actual exam question from Cisco's 300-730
Question #: 2
Topic #: 1
[All 300-730 Questions]

A second set of traffic selectors is negotiated between two peers using IKEv2. Which IKEv2 packet will contain details of the exchange?

  • A. IKEv2 IKE_SA_INIT
  • B. IKEv2 INFORMATIONAL
  • C. IKEv2 CREATE_CHILD_SA
  • D. IKEv2 IKE_AUTH
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
emaurri
6 months, 3 weeks ago
C Summary of Packet Flow IKE_SA_INIT: Both peers exchange this packet to initiate the IKE SA and negotiate parameters. IKE_AUTH: After the initial negotiation, peers authenticate and confirm the agreed-upon parameters, establishing the IKE SA. CREATE_CHILD_SA: This packet is used to create and negotiate IPsec SAs for the secure data transmission. NOTIFY: Used at any point to communicate status or errors, ensuring both sides are informed.
upvoted 1 times
...
Certife_dumps5
7 months, 4 weeks ago
Selected Answer: C
C is correct answer.
upvoted 1 times
...
lucidlynx
8 months ago
Selected Answer: C
C is correct. Informational is used just for errors, notifications, etc. https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/115936-understanding-ikev2-packet-exch-debug.html
upvoted 1 times
...
marges
1 year, 9 months ago
correct answer is c! The IKEv2 INFORMATIONAL exchange: is to convey control messages about errors and notifications so answer B is wrong.! The CREATE_CHILD_SA exchange is used to create new Child SAs and to rekey both IKE SAs and Child SAs. The initiator sends a CREATE_CHILD_SA request, containing a list of acceptable proposals for the Child SA. Each proposal defines an acceptable combination of attributes for the Child SA that is being negotiated (AH or ESP SA). The responder picks a proposal that is acceptable and returns the choice to the initiator in the CREATE_CHILD_SA response. The attributes that can be negotiated include the following: -Protocol (AH or ESP) -Authentication algorithm (for example, HMAC-MD5 or -HMAC-SHA) -Encapsulation mode (tunnel or transport) -Encryption algorithm (for example, DES, 3DES or AES) -Diffie-Hellman group information (for example, group 1, group 2, group 5 or group 14)
upvoted 1 times
...
netizen937
2 years, 1 month ago
Selected Answer: C
per ChatGPT (I know, use at your own risk...): The second set of traffic selectors negotiated between two peers using IKEv2 will be included in the CREATE_CHILD_SA exchange. This exchange is used to establish a new child SA within an existing IKE SA. The CREATE_CHILD_SA exchange is initiated by the initiator, and the responder replies with a CREATE_CHILD_SA response. The CREATE_CHILD_SA exchange contains the following payloads: Initiator's nonce SA proposal Traffic selector proposal Key exchange data IDi (Initiator's Identification) IDr (Responder's Identification) Authentication data The SA proposal and traffic selector proposal payloads will contain the details of the second set of traffic selectors negotiated between the peers. These proposals will include the specific traffic selectors for the new child SA, such as IP addresses and port numbers.
upvoted 2 times
...
Net4dd
2 years, 3 months ago
C. The IKEv2 CREATE_CHILD_SA packet is used to establish a new security association (SA) between two peers. This packet contains the details of the exchange, including the traffic selectors, the cryptographic algorithms and keys to be used, and any other relevant information.
upvoted 1 times
...
AF_Nick
2 years, 9 months ago
Selected Answer: C
C Create_Child_SA is correct.
upvoted 1 times
...
Tiptonlad
2 years, 11 months ago
Selected Answer: B
The information exchange would contain data exchanged between these two hosts. This would be found in the configuration payload of the INFOMRATION exchange. https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/115936-understanding-ikev2-packet-exch-debug.html
upvoted 3 times
...
nospampls
2 years, 12 months ago
Selected Answer: C
C Child_SA https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/115936-understanding-ikev2-packet-exch-debug.html
upvoted 3 times
...
[Removed]
2 years, 12 months ago
Selected Answer: C
...if additional CHILD_SAs are needed, a message called CREATE_CHILD_SA can be used to establish additional CHILD_SAs
upvoted 2 times
NullNull88
2 years, 6 months ago
The question starts with "A second set of traffic selectors is negotiated"
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago