300-420 exam dumps

300-420 practice question 205 of 323

Designing Cisco Enterprise Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-420 Question 205

Select 2

An enterprise is deploying Group Encrypted Transport VPN (GET VPN) to secure communication between branch locations over a private MPLS network. They need to ensure proper key management and scalability while maintaining a seamless failover mechanism in case of key server failure. Which of the following design considerations should they implement for a reliable GET VPN deployment?

  1. A

    Deploy redundant key servers with automatic failover configuration.

  2. B

    Use spoke-to-spoke encryption to minimize latency between branch locations.

  3. C

    Ensure the private MPLS network supports multicast traffic for key dissemination.

  4. D

    Configure GET VPN to use IKEv2 for initial peer authentication.

  5. E

    Deploy a secondary key server in passive mode with manual failover.

Show answer and explanation

Correct answers: A, C

Explanation

GET VPN is designed to secure group communications over private networks like MPLS by using group encryption. Multicast support is essential for efficient key distribution to all group members. Redundant key servers with automatic failover are critical for high availability and preventing any disruption in secure communication. These design considerations ensure a reliable and scalable GET VPN deployment.

  • A. Correct.

    Deploying redundant key servers with automatic failover ensures high availability and prevents communication disruption in case of a key server failure.

  • B. Incorrect.

    GET VPN does not rely on spoke-to-spoke encryption; instead, it uses a group-based encryption model for all traffic in the group. This option is incorrect.

  • C. Correct.

    GET VPN requires multicast for efficient key distribution to group members over the private MPLS network. Without multicast support, key dissemination may fail.

  • D. Incorrect.

    GET VPN does not mandate the use of IKEv2 for peer authentication. While IKEv2 can be used, it is not a specific requirement for GET VPN deployment.

  • E. Incorrect.

    A secondary key server in passive mode with manual failover is not ideal for scalability and reliability, as it introduces operational delays during failover situations.

Timed practice exam

Take a 300-420 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam