nerdexam
Cisco

300-730 · Question #97

What are two purposes of the key server in Cisco IOS GETVPN? (Choose two.)

The correct answer is B. to maintain encryption policies. The GETVPN key server centrally maintains group encryption policies and distributes keys to authenticated group members, ensuring consistent security across the group.

Secure Communications Architectures

Question

What are two purposes of the key server in Cisco IOS GETVPN? (Choose two.)

Options

  • Ato download encryption keys
  • Bto maintain encryption policies
  • Cto distribute routing information
  • Dto encrypt data traffic
  • Eto authenticate group members

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    94% (44)
  • D
    2% (1)
  • E
    2% (1)

Why each option

The GETVPN key server centrally maintains group encryption policies and distributes keys to authenticated group members, ensuring consistent security across the group.

Ato download encryption keys

Downloading encryption keys is the role of the group member, which registers with the key server to receive the TEK and KEK - the key server distributes rather than downloads keys.

Bto maintain encryption policiesCorrect

The key server stores and manages the Group Security Association (GSA) including encryption transforms, rekey timers, and security policies that all group members must enforce, providing a single authoritative policy source for the GETVPN domain. It distributes the Traffic Encryption Key (TEK) and Key Encryption Key (KEK) so that group members can encrypt and decrypt traffic using a shared, centrally controlled policy.

Cto distribute routing information

GETVPN does not manage or distribute routing information; routing is handled independently by the underlying WAN infrastructure and is outside the scope of the key server.

Dto encrypt data traffic

The key server does not participate in data-plane encryption; group members perform all data traffic encryption themselves using the keys and policies received from the key server.

Eto authenticate group members

While group member authentication occurs during the GETVPN registration process, it functions as a prerequisite mechanism supporting policy and key distribution rather than a standalone independent purpose of the key server.

Concept tested: Cisco IOS GETVPN key server roles and responsibilities

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-3s/sec-get-vpn-xe-3s-book/sec-get-vpn.html

Topics

#GETVPN#key server#encryption policy#group member authentication

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice