Which statements about IPsec pre-fragmentation (look-ahead fragmentation) are true? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Operates in tunnel mode only, Improves overall IPsec throughput because the end host can avoid reassembly after decryption..
Why this is the answer
IPsec pre-fragmentation, also known as look-ahead fragmentation, operates exclusively in tunnel mode. This is because tunnel mode encapsulates the entire original IP packet, allowing the IPsec gateway to fragment the encapsulated packet before encryption and the addition of the new IP header. Transport mode, in contrast, only encrypts the payload of the original IP packet, leaving the original IP header intact, which prevents pre-fragmentation by the IPsec device. Pre-fragmentation improves overall IPsec throughput by ensuring that packets are already fragmented to fit the MTU before encryption. This avoids the need for the receiving host to reassemble fragmented packets after decryption, which can be a CPU-intensive process. It is not independent of the physical interface MTU; rather, it is designed to optimize for it. It also supports Path MTU Discovery to determine the optimal fragment size.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed