Question 1
The number of BGP network commands that can be added to a router is based on what?
Correct Answer:
Based on RAM/NVRAM
Explanation:
The number of BGP network statements you can configure on a router is determined by the device’s memory resources. These statements are stored in the router’s configuration data (RAM as the running-config and NVRAM for the startup-config), and the BGP process must keep track of them and potentially advertise them. Since the protocol itself imposes no fixed cap on how many network statements there can be, the practical limit comes from how much RAM/NVRAM is available. It’s not limited by the number of neighbors, and it isn’t unlimited in real hardware.
Question 2
What is TTL Security Mechanism (TTLS) in BGP and what threat does it mitigate?
Correct Answer:
TTLS requires TTL=1 for eBGP sessions; it mitigates remote spoofed connections attempting to form BGP sessions.
Explanation:
TTL Security Mechanism uses the IP TTL field to bind a BGP session to the directly connected neighbor, so the router only accepts BGP TCP connections that come from a one-hop path. By configuring the session to require a TTL value of 1, any attempt to form a BGP session from a remote network (i.e., more than one hop away) is dropped, because the packet would have traversed at least one router and its TTL would not match the expected value. This significantly reduces the risk of remote spoofed connections where an attacker tries to impersonate a neighbor by forging the source IP to hijack or misrepresent routes. TTLS does not encrypt BGP updates, nor does it involve TTL proxies or a TTL-based path vector; its purpose is specifically to guard against spoofed, non-direct-neighbor session attempts by leveraging the hop-count constraint.
Question 3
Name the three well-known mandatory attributes.
Correct Answer:
AS path, Next Hop, Origin
Explanation:
In BGP, three attributes are required in every route update because they provide essential, universally-needed information about how the route arrived and how to reach it. The AS_PATH lists the sequence of autonomous systems the route has traversed. This helps prevent routing loops and supports policy decisions because you can see the path the update took across the Internet. The NEXT_HOP tells you the IP address of the next router to reach the destination; without this, a router wouldn’t know where to forward the packets. The ORIGIN attribute indicates how the route was learned—whether from an internal IGP, an external EGP, or if the origin is incomplete—so a router can make informed decisions when comparing multiple paths. The other attributes mentioned—Local Preference, Atomic Aggregate, Community, and Aggregator—are useful for shaping routing policies and route handling, but they’re not required to be present on every update. Local Preference is a local policy knob within an AS, Atomic Aggregate and Aggregator relate to how routes are summarized or who performed aggregation, and Community is a tagging mechanism for policy purposes.
Question 4
What fields does an Update message contain?
Correct Answer:
Withdrawn Routes, Path Attributes and Network Layer Reachability Information
Explanation:
An Update message in BGP communicates changes to the routing table. It consists of three parts: Withdrawn Routes (prefixes to remove), Path Attributes (metadata like AS_PATH, NEXT_HOP, ORIGIN, etc.), and NLRI (the new or announced prefixes). Withdrawn Routes removes previously advertised paths, Path Attributes apply to the routes being announced, and NLRI lists the prefixes that are now reachable. The Version, Hold Time, and Router ID belong to the OPEN message, not Update, and an Update message is not just NLRI alone.
Question 5
What is TCP-MD5 and when should you enable it on BGP sessions?
Correct Answer:
TCP-MD5 signs BGP messages at application layer.
Explanation:
TCP-MD5 secures the BGP session by authenticating the underlying TCP connection with a shared secret. It adds an MD5-based hash to TCP segments so both peers can verify that the other side knows the secret, preventing unauthorized peers from establishing or hijacking the BGP session. It does not encrypt BGP messages or sign them at the application layer, so confidentiality and per-message integrity beyond the TCP connection aren’t provided by TCP-MD5 itself. Enable TCP-MD5 when the route between peers traverses untrusted networks or there is a higher risk of spoofing, such as across the public Internet or between operators with potential misconfigurations. Configuration requires sharing the same secret on both ends; if the secret mismatches or one side doesn’t support it, the session will fail to establish. In short, TCP-MD5 protects the integrity of the TCP session used by BGP, not the content of BGP messages themselves, and is most useful where the risk of spoofed TCP connections is nontrivial.
Question 1
Exam overview

About this Exam

Prepare with the RIPE Border Gateway Protocol (BGP) Security Practice Test practice quiz. This question bank includes 10 questions covering security, attributes, local, ripe, and border. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

RIPE Border Gateway Protocol (BGP) Security Practice Test

This practice set contains 10 questions from the matching question bank and focuses on security, attributes, local, ripe, and border. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions