CND Practice Question: Network Security Controls Protocols And Devices
An enterprise network security team is analyzing BGP routing anomalies at the internet edge. An attacker is attempting to inject malicious routing updates to hijack corporate IP space (BGP prefix hijacking). Which mechanism should the network edge routers implement to cryptographically verify the origin autonomy of IP prefixes?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource Public Key Infrastructure (RPKI) with Route Origin Validation (ROV)
Resource Public Key Infrastructure (RPKP) allows resource holders to cryptographically associate IP address blocks with their legitimate Autonomous System Number (ASN) via Route Origin Authorizations (ROAs), preventing BGP hijacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Resource Public Key Infrastructure (RPKI) with Route Origin Validation (ROV)
Why this is correct
RPKI uses digital certificates to validate that an AS is authorized to originate a specific IP prefix, defending against BGP hijacking.
- ✗
DNSSEC zone signing across all authoritative name servers
Why it's wrong here
DNSSEC secures DNS record lookups against cache poisoning, not BGP routing table advertisements.
- ✗
OSPFv3 authentication trailers using HMAC-SHA-256
Why it's wrong here
OSPF is an interior gateway protocol (IGP) used within an enterprise network, whereas BGP prefix hijacking occurs at the exterior gateway (internet edge).
- ✗
IPsec Transport Mode with pre-shared keys
Why it's wrong here
IPsec secures unicast data packets between two endpoints, not inter-domain BGP routing control plane messages.
About these practice questions
Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.