How should Unknown/Not Found ROA validation statuses be handled in typical policy?

Master RIPE BGP Security with our comprehensive test. Understand the Border Gateway Protocol, explore multiple choice questions, and get ready for your exam with detailed hints and explanations.

Multiple Choice

How should Unknown/Not Found ROA validation statuses be handled in typical policy?

Explanation:
Unknown/Not Found ROA validation status means there is no ROA entry for the given prefix and origin AS in the RPKI data. Because there’s no proof of authorization, you can’t assume it’s legitimate or illegitimate. The right approach is to follow your established policy, which typically allows handling unknowns by either accepting with caution (monitoring, tagging, or applying stricter filtering) or rejecting the route. This avoids blindly trusting unknown routes or treating them as definitively valid. The other options force a single, absolute stance—always reject, always accept, or automatically convert to valid—that doesn’t reflect the uncertainty inherent in an unknown ROA status and can lead to security or connectivity problems.

Unknown/Not Found ROA validation status means there is no ROA entry for the given prefix and origin AS in the RPKI data. Because there’s no proof of authorization, you can’t assume it’s legitimate or illegitimate. The right approach is to follow your established policy, which typically allows handling unknowns by either accepting with caution (monitoring, tagging, or applying stricter filtering) or rejecting the route. This avoids blindly trusting unknown routes or treating them as definitively valid. The other options force a single, absolute stance—always reject, always accept, or automatically convert to valid—that doesn’t reflect the uncertainty inherent in an unknown ROA status and can lead to security or connectivity problems.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy