nerdexam
Cisco

400-007 · Question #351

Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The…

The correct answer is D. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and. The environment is a mixed transport network consisting of both MPLS Layer 3 VPN and point-to-point links. HIPAA requires encryption of protected health information in transit. IPsec point-to-point tunnels (Option D) can be deployed over any underlying transport - both MPLS and…

Designing Security

Question

Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The Info-Sec team has suggested to isolate production traffic end-to-end with an encryption over the transport network to comply with the HIPAA standard. Which solution must be used in their design if Company XYZ wants a quick roll out?

Options

  • AA firewall can be placed centrally to filter out the traffic based on required ports.
  • BVRF-Lite can be implemented toward the downstream network and VRF-based tunnels combined
  • CGETVPN can be implemented over the MPLS provider, which provides a payload encryption
  • DIPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and

How the community answered

(44 responses)
  • A
    20% (9)
  • B
    11% (5)
  • C
    5% (2)
  • D
    64% (28)

Explanation

The environment is a mixed transport network consisting of both MPLS Layer 3 VPN and point-to-point links. HIPAA requires encryption of protected health information in transit. IPsec point-to-point tunnels (Option D) can be deployed over any underlying transport - both MPLS and point-to-point links - making them universally applicable here and enabling a quick, consistent rollout. Option A (firewalls filtering by port) provides access control but no encryption, failing the HIPAA encryption requirement. Option B (VRF-Lite with VRF-based tunnels) provides traffic isolation but is complex to deploy quickly across a mixed topology. Option C (GETVPN) is excellent for all-MPLS networks where the provider core is trusted, as it uses a group key model and preserves original IP headers, but it is not designed to work across mixed topologies that include raw point-to-point links. IPsec tunnels are the most transport-agnostic and fastest to deploy in a heterogeneous environment.

Topics

#HIPAA#GETVPN#IPsec#MPLS encryption

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice