In IPsec, which mode encrypts only the payload?

Study for the WGU ITAS 2142 D830 Introduction to Cryptography Exam. Review flashcards and multiple choice questions with hints and explanations. Get ready for your exam!

Multiple Choice

In IPsec, which mode encrypts only the payload?

Explanation:
IPsec protects data in two ways: transport mode and tunnel mode. In transport mode, only the payload is encrypted and/or authenticated, while the original IP header remains in the clear so the packet can be routed normally. This makes transport mode ideal when end hosts communicate directly and you want confidentiality for the payload without hiding the addressing information. ESP handles the encryption, and it can work in transport mode to secure just the payload (or in tunnel mode to secure the entire original packet and add a new header). AH provides authentication without encryption, so it doesn’t encrypt the payload. Therefore, the mode that encrypts only the payload is transport mode.

IPsec protects data in two ways: transport mode and tunnel mode. In transport mode, only the payload is encrypted and/or authenticated, while the original IP header remains in the clear so the packet can be routed normally. This makes transport mode ideal when end hosts communicate directly and you want confidentiality for the payload without hiding the addressing information. ESP handles the encryption, and it can work in transport mode to secure just the payload (or in tunnel mode to secure the entire original packet and add a new header). AH provides authentication without encryption, so it doesn’t encrypt the payload. Therefore, the mode that encrypts only the payload is transport mode.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy