352-011 · Question #102
Your customer recently acquired a company with a national WAN of 750 locations consisting of MPLS network has MPLS VPN-based sites. Which solution ensure security and encryption across all sites to…
The correct answer is A. Implement a hierarchical DMVPN-based hub-and-spoke network with IPsec encryption. Option A is correct because DMVPN with IPsec provides overlay encryption that works across any IP transport - including two separate MPLS domains from a merger - while the hierarchical hub-and-spoke design scales efficiently to 750 sites and IPsec satisfies the audit's…
Question
Your customer recently acquired a company with a national WAN of 750 locations consisting of MPLS network has MPLS VPN-based sites. Which solution ensure security and encryption across all sites to meet an audit requirement?
Options
- AImplement a hierarchical DMVPN-based hub-and-spoke network with IPsec encryption
- BMigrate newly acquired sites to the MPLS VPN-based service of the parent company
- CImplement a GETVPN-based solution across all sites with selective traffic encryption
- DImplement a GETVPN-based solution across all sites with redundant key servers
How the community answered
(32 responses)- A81% (26)
- B9% (3)
- C3% (1)
- D6% (2)
Explanation
Option A is correct because DMVPN with IPsec provides overlay encryption that works across any IP transport - including two separate MPLS domains from a merger - while the hierarchical hub-and-spoke design scales efficiently to 750 sites and IPsec satisfies the audit's encryption mandate end-to-end.
Option B fails because standard MPLS VPN provides traffic isolation via label switching, not encryption; simply migrating sites to the parent's MPLS service leaves data unencrypted and fails the audit requirement.
Option C fails because selective traffic encryption means some traffic remains unencrypted, which would not satisfy a blanket audit requirement for encryption across all sites.
Option D is tempting - redundant key servers is actually a GET VPN best practice for high availability - but GET VPN is architected to operate within a single trusted MPLS cloud; it doesn't extend cleanly across two separate MPLS domains from different providers post-acquisition, making it architecturally unsuitable here.
Memory tip: Associate DMVPN with "Different networks, Merged securely" - when you're stitching together disparate or newly acquired networks across multiple providers and need guaranteed encryption everywhere, DMVPN + IPsec is the go-to overlay solution because it rides on top of whatever transport exists.
Topics
Community Discussion
No community discussion yet for this question.