400-007 · Question #351
Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The…
The correct answer is D. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and. The environment is a mixed transport network consisting of both MPLS Layer 3 VPN and point-to-point links. HIPAA requires encryption of protected health information in transit. IPsec point-to-point tunnels (Option D) can be deployed over any underlying transport - both MPLS and…
Question
Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The Info-Sec team has suggested to isolate production traffic end-to-end with an encryption over the transport network to comply with the HIPAA standard. Which solution must be used in their design if Company XYZ wants a quick roll out?
Options
- AA firewall can be placed centrally to filter out the traffic based on required ports.
- BVRF-Lite can be implemented toward the downstream network and VRF-based tunnels combined
- CGETVPN can be implemented over the MPLS provider, which provides a payload encryption
- DIPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and
How the community answered
(44 responses)- A20% (9)
- B11% (5)
- C5% (2)
- D64% (28)
Explanation
The environment is a mixed transport network consisting of both MPLS Layer 3 VPN and point-to-point links. HIPAA requires encryption of protected health information in transit. IPsec point-to-point tunnels (Option D) can be deployed over any underlying transport - both MPLS and point-to-point links - making them universally applicable here and enabling a quick, consistent rollout. Option A (firewalls filtering by port) provides access control but no encryption, failing the HIPAA encryption requirement. Option B (VRF-Lite with VRF-based tunnels) provides traffic isolation but is complex to deploy quickly across a mixed topology. Option C (GETVPN) is excellent for all-MPLS networks where the provider core is trusted, as it uses a group key model and preserves original IP headers, but it is not designed to work across mixed topologies that include raw point-to-point links. IPsec tunnels are the most transport-agnostic and fastest to deploy in a heterogeneous environment.
Topics
Community Discussion
No community discussion yet for this question.