nerdexam
Cisco

300-730 · Question #21

Which statement about GETVPN is true?

The correct answer is A. The configuration that defines which traffic to encrypt originates from the key server. In GETVPN, the key server centrally defines and distributes the traffic encryption policy as part of the Group Security Association to all registered group members.

Site-to-site VPNs on Routers and Firewalls

Question

Which statement about GETVPN is true?

Options

  • AThe configuration that defines which traffic to encrypt originates from the key server.
  • BTEK rekeys can be load-balanced between two key servers operating in COOP.
  • CThe pseudotime that is used for replay checking is synchronized via NTP.
  • DGroup members must acknowledge all KEK and TEK rekeys, regardless of configuration.

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    3% (1)
  • D
    7% (2)

Why each option

In GETVPN, the key server centrally defines and distributes the traffic encryption policy as part of the Group Security Association to all registered group members.

AThe configuration that defines which traffic to encrypt originates from the key server.Correct

The GETVPN key server is the authoritative source of policy - it defines the access control list specifying which traffic to encrypt and pushes this policy along with the Traffic Encryption Keys (TEKs) to all registered group members. Group members apply the policy received from the key server rather than configuring encryption policy locally.

BTEK rekeys can be load-balanced between two key servers operating in COOP.

In a COOP key server configuration, one key server is elected primary and performs all rekeys while the secondary is a hot standby that only takes over if the primary fails - TEK rekeys are not load-balanced between the two.

CThe pseudotime that is used for replay checking is synchronized via NTP.

GETVPN anti-replay uses a pseudotime value distributed by the key server to group members as part of the Group SA, making it independent of NTP and not synchronized via NTP.

DGroup members must acknowledge all KEK and TEK rekeys, regardless of configuration.

GETVPN supports both unicast and multicast rekey methods - multicast rekey does not require acknowledgment from group members, so whether acknowledgment is required depends on the configured rekey transport method.

Concept tested: GETVPN key server centralized traffic encryption policy distribution

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-conn-getvpn-xe-16-book/sec-conn-getvpn-getvpn.html

Topics

#GETVPN#key server#TEK rekey#COOP

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice