ETExamTower
Q27Application Deployment and SecurityMultiple answers

Refer to the exhibit. Which two functions does the load balancer perform when it handles Internet-originated traffic destined for an application hosted on the file server farm? (Choose two.)

Question exhibit
Select 2 answers.
← → navigate · a answer
Community votes
D
50% (7)
C
36% (5)
E
14% (2)
A
0% (0)
B
0% (0)
Discussion · 21
12
I’d say C and D depending on the protocol (HTTP or HTTPS). A and B are probably wrong, because UDP works with DTLS rather than TLS.
7
C and D A and B cannot be right, since connectionless UDP will not map to connection-oriented TCP, which http and https use E cannot be true, as SCTP is a stream control protocol and cannot be mapped to http In both C and D the LB terminates TLS, and originates the http connection, either encrypted (HTTP), or not encrypted (HTTPS=HTTP+TLS) way.
4
C and D for me. The load balancer would terminate TCP on the front-end and re-initiate another HTPP or HTTPS connection on the back-end. Only TCP is used for HTTP connections and not UDP. The SCTP option makes little sense.
C, D 3
Selected Answer: CD Neither UDP nor SCTP are relevant
3
C and D are the correct answer. The traffic from the router comes via the internet, so the LB should secure it and use TLS to terminate the connection from the router. And the LB should handle the SSL offloading. Then from the LB, it will create a new session originating from the LB (via selfIPs) and decide whether to use HTTP or HTTPS to the server.
2
I don't think I've ever configured SCTP on a load balancer, and it's not really a 'security' protocol. Also, a ton of load balancers don't even know how to differentiate them (https://support.f5.com/csp/article/K3800)
2
The question is wrongly formulated and not complete. What is it originated from the router or a user making website requests i.e. what client and destination application is used being handled. I would say C and D.
D, E 2
Selected Answer: DE https 443/sctp HTTPS # IETF TSVWG # Randall Stewart <[email protected]> # [RFC4960] World Wide Web HTTP over TLS/SSL over SCTP.
D, E 2
Selected Answer: DE TLS isn't used with HTTP connections :)
C, D 2
Selected Answer: CD C and D relate to HTTPS with or without SSL offloading.
2
Tend to think it is - DE TLS with HTTPs is obvious. And from the rest, the only protocol that supports TLS is SCTP. UDP is using DTLS. And HTTP is NOT using TLS at all.
C, D 2
Selected Answer: CD In the context of load balancing, TLS termination is usually handled over a TCP connection. UDP and SCTP are less common for this use case due to the lack of reliability compared to TCP, especially for applications such as file servers. Once TLS is terminated, the load balancer can then initiate a new connection to the selected server. This can be either HTTP or HTTPS depending on the specific needs of the network and application, although using HTTP is more common after termination because the load balancer has already decrypted the traffic and can then send it unencrypted to the server in a secure network. Given these considerations, the two correct options are: C. Terminate the TLS over the TCP connection from the router and originate an HTTP connection to the selected server. D. Terminate the TLS over the TCP connection from the router and originate an HTTPS connection to the selected server.
1
I would agree with JM_Lee. TLS provides security (HTTPS), so in my opinion it would be DE
1
D and E for sure
1
C is a concept called SSL/TLS offloader aka SSL/TLS Termination. C and D are correct! SCTP has nothing to do with HTTP and HTTPS.
1
you guys did not notice the file server farm? nothing to do with sctp. c and d are correct
1
Agree: https://www.rfc-editor.org/rfc/rfc3436
C, D 1
Selected Answer: CD Stream Control Transmission Protocol (SCTP) uses DTLS DTLS is a protocol built on TLS that can secure the datagram transport. DTLS is well-suited for securing applications and services that are delay-sensitive (and hence use datagram transport), tunneling applications such as VPNs, and applications that tend to run out of file descriptors or socket buffers. https://datatracker.ietf.org/doc/html/rfc9260
1
https://www.ietf.org/proceedings/54/I-D/draft-ietf-tsvwg-tls-over-sctp-00.txt - about E
1
Disagree.. from your link 6.2. TLS-based user data transmission In general, the bi-directional stream will be used for TLS-based user data transmission and it SHOULD NOT be used for SCTP-based user data transmission. The exception to this rule is for protocols that contain upgrade-to-TLS mechanisms, such as those of HTTP upgrade [RFC2817]
1
Good because there are two connections. One to LB and one to Server. This is known as SSL offloading when TLS is terminated on the load balancer and http goes to the server so as to remove the ssl processing from the server, which does not have dedicated crypto hardware.