🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization has established an IPsec site-to-site VPN between its on-premises firewall and an AWS virtual private gateway. During performance testing, large file transfers (packets over about 1400 bytes) consistently fail, while small pings succeed. Packet captures show repeated ICMP "fragmentation needed" messages and no ESP packets larger than 1420 bytes. Which common IPsec deployment issue is most likely responsible for this behavior?

  • Phase 1 is configured for aggressive mode instead of main mode, leading to periodic re-authentication and packet loss.

  • Perfect Forward Secrecy (PFS) is disabled, so the reuse of keying material triggers replay protection and discards large packets.

  • The VPN is using transport mode rather than tunnel mode, so exposed inner headers are being filtered by intermediate routers.

  • ESP overhead causes packets to exceed the path MTU, and with the DF bit set they cannot be fragmented, so large packets are dropped.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot