nerdexam
Cisco

300-320 · Question #426

When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)

The correct answer is C. packets per second capabilities D. maximum tunnel termination capabilities. For IPSec headend scalability, Packets Per Second (PPS) capability (C) and maximum tunnel termination count (D) are the most accurate indicators. PPS directly measures how fast the device can encrypt and decrypt packets - IPSec is computationally intensive per packet, so PPS…

Security Services

Question

When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)

Options

  • ACPU capabilities
  • Bbandwidth capabilities
  • Cpackets per second capabilities
  • Dmaximum tunnel termination capabilities

How the community answered

(54 responses)
  • A
    19% (10)
  • B
    9% (5)
  • C
    72% (39)

Explanation

For IPSec headend scalability, Packets Per Second (PPS) capability (C) and maximum tunnel termination count (D) are the most accurate indicators. PPS directly measures how fast the device can encrypt and decrypt packets - IPSec is computationally intensive per packet, so PPS reflects real encryption throughput. Maximum tunnel termination count (D) defines how many simultaneous IPSec sessions the device can maintain, which directly determines how many remote users or branch sites can connect. CPU (A) and bandwidth (B) are contributing factors but are less precise - a device may have high bandwidth but a low PPS rate due to encryption overhead, making PPS the more accurate metric.

Topics

#IPSec#VPN headend#scalability#tunnel termination

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice