What are typical ROA validation statuses and how should each influence route acceptance?

Master RIPE BGP Security with our comprehensive test. Understand the Border Gateway Protocol, explore multiple choice questions, and get ready for your exam with detailed hints and explanations.

Multiple Choice

What are typical ROA validation statuses and how should each influence route acceptance?

Explanation:
ROA validation statuses guide how to treat each BGP route. If a route is Valid, that prefix and AS are explicitly authorized by the ROA, so the route should be accepted and often given favorable routing priority. If a route is Invalid, the origin is not covered by any valid ROA for that prefix, so it should be rejected or deprioritized to protect against misoriginations or potential hijacks. If the status is Unknown or Not Found (no ROA entry for that prefix), there isn’t enough validation evidence; handling this depends on policy—many operators either accept with caution or reject, rather than treating Unknown as simply inconsequential. The core idea is: Valid = trust and accept; Invalid = do not trust (reject or deprioritize); Unknown = policy-driven, potentially degrade or monitor.

ROA validation statuses guide how to treat each BGP route. If a route is Valid, that prefix and AS are explicitly authorized by the ROA, so the route should be accepted and often given favorable routing priority. If a route is Invalid, the origin is not covered by any valid ROA for that prefix, so it should be rejected or deprioritized to protect against misoriginations or potential hijacks. If the status is Unknown or Not Found (no ROA entry for that prefix), there isn’t enough validation evidence; handling this depends on policy—many operators either accept with caution or reject, rather than treating Unknown as simply inconsequential. The core idea is: Valid = trust and accept; Invalid = do not trust (reject or deprioritize); Unknown = policy-driven, potentially degrade or monitor.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy