Courseiva
hardMultiple Select

CISSP Practice Question: Which three BGP security mechanisms help protect…

Which three BGP security mechanisms help protect against route hijacking? (Choose THREE.)

⚠ Common exam trap

ISC2 often tests the distinction between BGP security mechanisms that prevent hijacking (RPKI, prefix filtering, MD5 authentication) versus those that influence routing policy or traffic engineering (MED, Flowspec), leading candidates to mistakenly select MED or Flowspec as hijacking protections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource Public Key Infrastructure (RPKI)

RPKI (A) is correct because it creates a cryptographically signed mapping between IP prefixes and their authorized origin ASes, allowing routers to validate BGP origin announcements via Route Origin Authorizations (ROAs) and reject or deprioritize hijacked routes. Prefix filtering on edge routers (C) is correct because explicitly permitting only known, legitimate prefixes (and their expected prefix lengths) blocks unauthorized or more-specific announcements that a hijacker would use to attract traffic. MD5 authentication between BGP peers (E) is correct because it uses a shared secret and TCP MD5 signature option to authenticate each BGP segment, preventing an attacker from injecting forged BGP updates or resetting the session by spoofing a peer. BGP Flowspec (B) is not a route-hijacking protection; it distributes traffic-flow filtering rules to mitigate DDoS and similar attacks, not to validate prefix ownership. The BGP MED attribute (D) is merely a non-transitive, optional path-selection metric for influencing inbound traffic, and it provides no authentication or anti-hijacking capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Resource Public Key Infrastructure (RPKI)

    Why this is correct

    Resource Public Key Infrastructure (RPKI) provides a cryptographic framework for verifying the legitimate origin of IP address blocks. It allows IP address holders to create cryptographically signed statements, called Route Origin Authorizations (ROAs), which specify which Autonomous Systems (ASes) are authorized to originate their prefixes. BGP routers can then validate incoming route announcements against these ROAs, rejecting any routes that are not authorized, thereby directly mitigating route hijacking and mis-origination.

  • ✗

    BGP Flowspec

    Why it's wrong here

    BGP Flowspec is an extension to BGP that allows for the distribution of traffic filtering rules across a network. It enables network operators to dynamically propagate granular filtering policies, such as blocking specific source/destination IPs, ports, or protocols, to mitigate DDoS attacks or enforce traffic engineering. While a valuable security tool for traffic management, Flowspec does not protect against route hijacking because it operates on the data plane to filter traffic, not on the control plane to validate the authenticity or origin of BGP route announcements themselves.

  • ✓

    Prefix filtering on edge routers

    Why this is correct

    Prefix filtering on edge routers involves configuring access control lists (ACLs) or route-maps to explicitly permit or deny specific IP prefixes from being advertised or accepted. By carefully defining which prefixes are expected from neighboring ASes and which prefixes an AS is authorized to originate, network operators can prevent the propagation of unauthorized or incorrect route announcements. This mechanism acts as a critical first line of defense, blocking malicious or erroneous route advertisements at the network's boundary before they can impact internal routing tables.

  • ✗

    BGP MED attribute

    Why it's wrong here

    The BGP Multi-Exit Discriminator (MED) attribute is an optional, non-transitive attribute used to influence the inbound path selection for traffic entering an Autonomous System (AS) from a neighboring AS. A lower MED value is generally preferred, indicating a more desirable path. While MED is crucial for traffic engineering and optimizing network ingress, it is purely a path selection metric and provides no mechanism for authenticating the origin or legitimacy of a BGP route announcement, thus offering no protection against route hijacking.

  • ✓

    MD5 authentication between BGP peers

    Why this is correct

    MD5 authentication between BGP peers involves configuring a shared secret key on both ends of a BGP session. Every BGP message exchanged between these peers is then cryptographically signed using this key, and the receiving peer verifies the signature. This mechanism ensures the integrity and authenticity of BGP updates, preventing unauthorized third parties from injecting forged BGP messages or tampering with legitimate route announcements by hijacking the TCP session itself. It secures the control plane communication channel, making it a fundamental defense against session-level attacks.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.