nerdexam
Cisco

352-001 · Question #111

When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)

The correct answer is C. packets per second capabilities D. maximum tunnel termination capabilities. Packets per second throughput and maximum tunnel termination count are the most accurate scalability indicators for an IPSec headend because they directly measure cryptographic forwarding capacity and concurrent session limits.

Designing Security

Question

When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)

Options

  • ACPU capabilities
  • Bbandwidth capabilities
  • Cpackets per second capabilities
  • Dmaximum tunnel termination capabilities

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    18% (5)
  • C
    71% (20)

Why each option

Packets per second throughput and maximum tunnel termination count are the most accurate scalability indicators for an IPSec headend because they directly measure cryptographic forwarding capacity and concurrent session limits.

ACPU capabilities

CPU capability is a hardware attribute that influences performance but is not an accurate standalone scalability indicator - devices with similar CPUs can differ greatly in IPSec performance depending on hardware crypto offload engines and dedicated ASICs.

Bbandwidth capabilities

Bandwidth capability describes raw interface throughput and does not account for the per-packet cryptographic processing overhead of IPSec, making it an insufficient indicator of actual encrypted traffic scalability.

Cpackets per second capabilitiesCorrect

Packets per second measures the rate at which the device can encrypt, decrypt, and forward IPSec-protected traffic, directly reflecting the device's cryptographic processing capacity and where it will bottleneck under load.

Dmaximum tunnel termination capabilitiesCorrect

Maximum tunnel termination capability defines the upper limit of concurrent IPSec sessions the device can maintain, making it the most precise metric for determining how many remote sites or clients the headend can scale to support.

Concept tested: IPSec VPN headend scalability performance indicators

Source: https://www.cisco.com/c/en/us/products/collateral/security/asr-1000-series-aggregation-services-routers/white-paper-c11-737906.html

Topics

#IPSec headend#scalability#tunnel termination#packets per second

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice