What are purposes of the Internet Key Exchange in an IPsec VPN? (Choose two.)
A . The Internet Key Exchange protocol establishes security associations
B . The Internet Key Exchange protocol provides data confidentiality
C . The Internet Key Exchange protocol provides replay detection
D . The Internet Key Exchange protocol is responsible for mutual authentication
Answer: A,D
Explanation:
IPsec uses the Internet Key Exchange (IKE) protocol to negotiate and establish secured site-tosite or remote access virtual private network (VPN) tunnels. IKE is a framework provided by the Internet Security Association and Key Management Protocol (ISAKMP) and parts of two other key management protocols, namely Oakley and Secure Key Exchange Mechanism (SKEME). In IKE Phase 1 IPsec peers negotiate and authenticate each other. In Phase 2 they negotiate keying materials and algorithms for the encryption of the data being transferred over the IPsec tunnel.
Source: Cisco Official Certification Guide, The Internet Key Exchange (IKE) Protocol, p.123