nerdexam
Cisco

400-007 · Question #28

Company XYZ has 30 sites running a legacy private WAN architecture that connects to the Internet via multiple high-speed connections. The company is now redesigning their network and must comply…

The correct answer is B. IPsec C. DMVPN. DMVPN provides scalable dynamic spoke-to-spoke connectivity over the Internet, and IPsec secures corporate data traversing that overlay network.

Designing Network Infrastructure

Question

Company XYZ has 30 sites running a legacy private WAN architecture that connects to the Internet via multiple high-speed connections. The company is now redesigning their network and must comply with these design requirements:

  • Use a private WAN strategy that allows the sites to connect to each

other directly and caters for future expansion

  • Use the Internet as the underlay for the private WAN
  • Securely transfer the corporate data over the private WAN

Which two technologies should be incorporated into the design of this network? (Choose two.)

Options

  • AS-VTI
  • BIPsec
  • CDMVPN
  • DGET VPN
  • EPPTP

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    76% (19)
  • D
    4% (1)
  • E
    12% (3)

Why each option

DMVPN provides scalable dynamic spoke-to-spoke connectivity over the Internet, and IPsec secures corporate data traversing that overlay network.

AS-VTI

S-VTI creates static point-to-point tunnel interfaces that require manual configuration for every peer pair and do not support the dynamic spoke-to-spoke connectivity needed for 30+ sites.

BIPsecCorrect

IPsec provides the cryptographic security layer required to protect corporate data in transit across the Internet-based overlay, satisfying the requirement for secure data transfer over the private WAN.

CDMVPNCorrect

DMVPN enables dynamic multipoint connectivity so sites communicate directly without hub-mediated tunnels, uses the Internet as the underlay transport via mGRE, and scales easily for future site additions through NHRP dynamic registration.

DGET VPN

GET VPN is designed for private MPLS or trusted private WAN underlays because it preserves original IP headers and relies on a multicast-capable private network - it cannot function over the public Internet.

EPPTP

PPTP is a deprecated tunneling protocol with known cryptographic weaknesses (MS-CHAPv2, RC4) that fails the requirement for secure corporate data transfer.

Concept tested: DMVPN and IPsec for scalable secure Internet-overlay WAN

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/WAN_and_MAN/DMVPN/DMVPN_2_Phase2.html

Topics

#DMVPN#IPsec#private WAN#VPN design

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice