nerdexam
Cisco

352-011 · Question #92

Which two options are considered risks or concerns when both the Internet and VPN service functions are on the same PE router? (Choose two.)

Correct Answers: A and D Placing both Internet and VPN services on the same PE router creates a security exposure and a single point of failure. For (A), Internet-facing traffic brings exposure to attacks like DDoS, which can exhaust the router's CPU, memory, or bandwidth…

Service Provider Network Design

Question

Which two options are considered risks or concerns when both the Internet and VPN service functions are on the same PE router? (Choose two.)

Options

  • AInternet-based attacks can affect VPN customers.
  • BBGP cannot simultaneously run on the PE router that runs MPLS.
  • CMP-BGP prefixes increase routers' global routing tables, which affects network convergence.
  • DFailure on the PE router affects both VPN and Internet services.
  • ECustomer performance can be affected by VPN traffic if Internet-based traffic is not prioritized on

Explanation

Correct Answers: A and D

Placing both Internet and VPN services on the same PE router creates a security exposure and a single point of failure. For (A), Internet-facing traffic brings exposure to attacks like DDoS, which can exhaust the router's CPU, memory, or bandwidth - directly degrading service for VPN customers sharing that same hardware. For (D), the router becomes a single point of failure: any hardware fault, software crash, or overload event takes down both services simultaneously, compounding the business impact.

Why the distractors are wrong:

  • B is false - MP-BGP routinely runs alongside MPLS on PE routers; it's a foundational design of MPLS L3VPN
  • C is false - VPN prefixes live in isolated VRFs, not the global routing table, which is precisely why MPLS VPNs scale well
  • E is backwards in its logic - if Internet traffic is not prioritized, VPN traffic benefits, not suffers; the real risk is the opposite (Internet traffic starving VPN traffic)

Memory tip: Think of the PE router as a shared apartment - if a rowdy neighbor (Internet traffic/attacks) moves in, they disturb the quiet tenants (VPN customers), and if the building burns down (router failure), everyone loses their home. The two risks = contamination and co-failure.

Topics

#PE Router Design#VPN/Internet Co-location#Network Segmentation#High Availability

Community Discussion

No community discussion yet for this question.

Full 352-011 Practice