nerdexam
Cisco

352-011 · Question #102

Your customer recently acquired a company with a national WAN of 750 locations consisting of MPLS network has MPLS VPN-based sites. Which solution ensure security and encryption across all sites to…

The correct answer is A. Implement a hierarchical DMVPN-based hub-and-spoke network with IPsec encryption. Option A is correct because DMVPN with IPsec provides overlay encryption that works across any IP transport - including two separate MPLS domains from a merger - while the hierarchical hub-and-spoke design scales efficiently to 750 sites and IPsec satisfies the audit's…

Enterprise Network Design

Question

Your customer recently acquired a company with a national WAN of 750 locations consisting of MPLS network has MPLS VPN-based sites. Which solution ensure security and encryption across all sites to meet an audit requirement?

Options

  • AImplement a hierarchical DMVPN-based hub-and-spoke network with IPsec encryption
  • BMigrate newly acquired sites to the MPLS VPN-based service of the parent company
  • CImplement a GETVPN-based solution across all sites with selective traffic encryption
  • DImplement a GETVPN-based solution across all sites with redundant key servers

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    9% (3)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Option A is correct because DMVPN with IPsec provides overlay encryption that works across any IP transport - including two separate MPLS domains from a merger - while the hierarchical hub-and-spoke design scales efficiently to 750 sites and IPsec satisfies the audit's encryption mandate end-to-end.

Option B fails because standard MPLS VPN provides traffic isolation via label switching, not encryption; simply migrating sites to the parent's MPLS service leaves data unencrypted and fails the audit requirement.

Option C fails because selective traffic encryption means some traffic remains unencrypted, which would not satisfy a blanket audit requirement for encryption across all sites.

Option D is tempting - redundant key servers is actually a GET VPN best practice for high availability - but GET VPN is architected to operate within a single trusted MPLS cloud; it doesn't extend cleanly across two separate MPLS domains from different providers post-acquisition, making it architecturally unsuitable here.

Memory tip: Associate DMVPN with "Different networks, Merged securely" - when you're stitching together disparate or newly acquired networks across multiple providers and need guaranteed encryption everywhere, DMVPN + IPsec is the go-to overlay solution because it rides on top of whatever transport exists.

Topics

#DMVPN#IPsec Encryption#Hub-and-spoke Topology#WAN Scalability

Community Discussion

No community discussion yet for this question.

Full 352-011 Practice