300-410 VPN Technologies Practice Question
A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?
⚠ Common exam trap
The trap here is thinking that rekey requires re-registration or is only for control plane, when it actually pushes new data plane keys to members.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.
GET VPN uses GDOI for group key management. The key server sends rekey messages to group members to update encryption keys and policies. This allows scalable key distribution without re-registration. The rekey command configures the key server's rekey behavior, including algorithms and lifetimes. It directly impacts data plane keys, ensuring secure and efficient key rollover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rekey mechanism only applies to the control plane and does not affect data plane encryption keys.
Why it's wrong here
Rekey messages are used to refresh the actual data plane encryption keys (TEKs) used to encrypt traffic. They are critical for maintaining security and forward secrecy. The rekey mechanism directly affects the keys used for data encryption, not just control plane communication. Therefore, this statement is incorrect.
- ✓
The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.
Why this is correct
In GET VPN, the key server manages the GDOI protocol and distributes encryption keys to group members. The `rekey` command configures the key server to send rekey messages, which contain new keys or policies, to group members. This ensures that group members can update their keys without re-registering, maintaining secure communication.
- ✗
The rekey command is used to manually trigger a key rollover on the key server.
Why it's wrong here
The `rekey` command in GET VPN configuration is not for manual triggering; it defines the rekey policy and parameters, such as the rekey algorithm and lifetime. The key server automatically sends rekey messages based on configured timers or policy changes. Manual triggering is not typical and not the purpose of this command.
- ✗
The rekey mechanism requires each group member to initiate a new registration with the key server.
Why it's wrong here
Rekey messages are pushed from the key server to the group members; they do not require group members to re-register. Re-registration occurs only when a group member initially joins or after a failure. The rekey process is designed to be efficient and scalable, avoiding the overhead of re-registration for key updates.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.