A grain-elevator auditor rejects the VPN gateway’s default IPsec/IKE proposal as a legacy cipher set. What should the security engineer apply on the site-to-site connection?
Select an answer to reveal the explanation.
Short Explanation
Default VPN proposals are the factory combo meal—auditors want the chef’s special. Slap a custom IPsec/IKE policy on the connection with IKEv2 and modern crypto instead of shrugging that “VPN equals done.”
Full Explanation
Azure VPN Gateway site-to-site connections can use a custom IPsec/IKE policy so you select IKEv2 and stronger encryption and integrity algorithms instead of accepting a weaker default proposal. Encryption existing in some form does not satisfy a requirement to harden the proposal. ExpressRoute private peering is a different path and is not encrypted by default; NSG allows do not replace IPsec on the tunnel.