CS6250 BUNDLE TEST BANK ACTUAL
QUESTIONS AND VERIFIED RESPONSES
FULL SOLUTION
⩥ How does SDX apply OUTBOUND policies?
Answer: Applied on traffic from participant's virtual switch port towards
other participants
(8)
⩥ What is the difference between a traditional IXP and SDX
architecture?
Answer: traditional: participants connect to shared layer 2 network and
BGP route server. layer 2 forwards packets. route server exchanges
routing info
SDX: AS has VIRTUAL SDN switch - connects border router to every
other participant to AS
- AS defines forwarding policies if it is only participant at SDX- does
NOT influence how other participants forward packets on their switches
(8)
⩥ What are 4 applications of SDX in domain of wide area traffic
delivery?
,Answer: 1. app-specific peering
2. inbound traffic engineering
3. wide area load balancing
4. redirection thru middleboxes
(8)
⩥ How does SDX allow app-specific peering?
Answer: - identify traffic from app and direct to different path
- good for high-bandwidth apps
(8)
⩥ How does SDX allow inbound traffic engineering?
Answer: installing the switch with forwarding rules based on source IP
and source port (INSTEAD OF JUST DEST ADDRESS) enables the AS
to control how TRAFFIC ENTERS THE NETWORK
(8)
⩥ How does SDX support wide-area server load balancing?
Answer: - SDX allows us to modify packet headers
- Destination IPs can be modified at the IXP to desired backend behavior
(8)
,⩥ How does SDX support redirection thru middleboxes?
Answer: - middleboxes don't have to be placed at EVERY location in
case of geographically large ISPs
- direct traffic through a fixed set of middleboxes
- less redirection - send some traffic to a SEQUENCE of middleboxes
(8)
⩥ What are the 4 properties that ensure communication is secure even in
presence of attackers? Countermeasures for each.
Answer: 1. confidentiality
- message is only available to 2 parties
- encrypt the message
2. integrity
- message has not been modified while in transit
- check for message integrity
3. Authentication
- 2 parties are who they say they are
- authentication mechanisms
, 4. availability
- communication channel is functioning properly and power
outages/attacks can be coped with
(9)
⩥ What is ultimate goal of DNS protocol abuse?
Answer: Remain undetectable longer
(9)
⩥ What is the purpose of Round Robin DNS?
Answer: - distribute load of requests to several servers at 1 location
- purpose is to distribute traffic evenly across destination IPs
(9)
⩥ How does round robin work? (RRDNS)
Answer: DNS client chooses record with a strategy
Record has a time to live (TTL) - validity of response
QUESTIONS AND VERIFIED RESPONSES
FULL SOLUTION
⩥ How does SDX apply OUTBOUND policies?
Answer: Applied on traffic from participant's virtual switch port towards
other participants
(8)
⩥ What is the difference between a traditional IXP and SDX
architecture?
Answer: traditional: participants connect to shared layer 2 network and
BGP route server. layer 2 forwards packets. route server exchanges
routing info
SDX: AS has VIRTUAL SDN switch - connects border router to every
other participant to AS
- AS defines forwarding policies if it is only participant at SDX- does
NOT influence how other participants forward packets on their switches
(8)
⩥ What are 4 applications of SDX in domain of wide area traffic
delivery?
,Answer: 1. app-specific peering
2. inbound traffic engineering
3. wide area load balancing
4. redirection thru middleboxes
(8)
⩥ How does SDX allow app-specific peering?
Answer: - identify traffic from app and direct to different path
- good for high-bandwidth apps
(8)
⩥ How does SDX allow inbound traffic engineering?
Answer: installing the switch with forwarding rules based on source IP
and source port (INSTEAD OF JUST DEST ADDRESS) enables the AS
to control how TRAFFIC ENTERS THE NETWORK
(8)
⩥ How does SDX support wide-area server load balancing?
Answer: - SDX allows us to modify packet headers
- Destination IPs can be modified at the IXP to desired backend behavior
(8)
,⩥ How does SDX support redirection thru middleboxes?
Answer: - middleboxes don't have to be placed at EVERY location in
case of geographically large ISPs
- direct traffic through a fixed set of middleboxes
- less redirection - send some traffic to a SEQUENCE of middleboxes
(8)
⩥ What are the 4 properties that ensure communication is secure even in
presence of attackers? Countermeasures for each.
Answer: 1. confidentiality
- message is only available to 2 parties
- encrypt the message
2. integrity
- message has not been modified while in transit
- check for message integrity
3. Authentication
- 2 parties are who they say they are
- authentication mechanisms
, 4. availability
- communication channel is functioning properly and power
outages/attacks can be coped with
(9)
⩥ What is ultimate goal of DNS protocol abuse?
Answer: Remain undetectable longer
(9)
⩥ What is the purpose of Round Robin DNS?
Answer: - distribute load of requests to several servers at 1 location
- purpose is to distribute traffic evenly across destination IPs
(9)
⩥ How does round robin work? (RRDNS)
Answer: DNS client chooses record with a strategy
Record has a time to live (TTL) - validity of response