Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?

⚠ Common exam trap

The trap here is thinking that rekey requires re-registration or is only for control plane, when it actually pushes new data plane keys to members.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.

GET VPN uses GDOI for group key management. The key server sends rekey messages to group members to update encryption keys and policies. This allows scalable key distribution without re-registration. The rekey command configures the key server's rekey behavior, including algorithms and lifetimes. It directly impacts data plane keys, ensuring secure and efficient key rollover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The rekey mechanism only applies to the control plane and does not affect data plane encryption keys.

    Why it's wrong here

    Rekey messages are used to refresh the actual data plane encryption keys (TEKs) used to encrypt traffic. They are critical for maintaining security and forward secrecy. The rekey mechanism directly affects the keys used for data encryption, not just control plane communication. Therefore, this statement is incorrect.

  • ✓

    The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.

    Why this is correct

    In GET VPN, the key server manages the GDOI protocol and distributes encryption keys to group members. The `rekey` command configures the key server to send rekey messages, which contain new keys or policies, to group members. This ensures that group members can update their keys without re-registering, maintaining secure communication.

  • ✗

    The rekey command is used to manually trigger a key rollover on the key server.

    Why it's wrong here

    The `rekey` command in GET VPN configuration is not for manual triggering; it defines the rekey policy and parameters, such as the rekey algorithm and lifetime. The key server automatically sends rekey messages based on configured timers or policy changes. Manual triggering is not typical and not the purpose of this command.

  • ✗

    The rekey mechanism requires each group member to initiate a new registration with the key server.

    Why it's wrong here

    Rekey messages are pushed from the key server to the group members; they do not require group members to re-register. Re-registration occurs only when a group member initially joins or after a failure. The rekey process is designed to be efficient and scalable, avoiding the overhead of re-registration for key updates.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.