300-410 VPN Technologies Practice Question
A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?
⚠ Common exam trap
The trap here is assuming that any key-distribution need is solved by IKE, when GET VPN specifically relies on GDOI for group key and rekey delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Group Domain of Interpretation (GDOI)
GET VPN uses the Group Domain of Interpretation so that a key server can distribute a shared Group Security Association and push rekey messages to all group members. Members register with the key server, obtain the same keys and policies, and then encrypt traffic directly with one another over the provider network without building point-to-point tunnels. This preserves the any-to-any model and keeps rekeying centralized on the key server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IKEv2 with a hub-and-spoke profile on the key server
Why it's wrong here
IKEv2 negotiates per-peer SAs and is designed for point-to-point tunnel establishment between two peers. In a GET VPN design, group members do not run IKE with each other or with the key server for data traffic; they share a common Group Security Association. Using IKEv2 here would create per-tunnel SAs and defeat the any-to-any tunnel-less model that the key server's rekey mechanism is built to support.
- ✓
Group Domain of Interpretation (GDOI)
Why this is correct
GDOI is the protocol the key server uses in GET VPN to distribute the Group Security Association, including the rekey messages carrying updated keys and policies. Group members register with the key server over GDOI, receive the shared keys, and then encrypt traffic directly between themselves without per-pair tunnels. This matches the requirement for identical keys pushed from a single key server.
- ✗
IPsec SA negotiation using ISAKMP aggressive mode
Why it's wrong here
Aggressive mode is an IKEv1 Phase 1 exchange used to speed up peer authentication, typically for remote-access clients with dynamic addresses. It negotiates pairwise IKE and IPsec SAs and does not implement group key distribution. GET VPN requires a Group Security Association shared by all members, which aggressive mode cannot supply, so this would not satisfy the identical-key requirement.
- ✗
NHRP with a next-hop server mapping
Why it's wrong here
NHRP is the resolution protocol used by DMVPN to map tunnel addresses to NBMA addresses so spokes can build on-demand tunnels. It does not distribute encryption keys and has no rekey message format. Deploying NHRP in a GET VPN design would not provide the Group Security Association or the periodic rekey push the key server must deliver to every group member.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
MPLS L3VPN Basics
Key term
GET VPN
Group Encrypted Transport VPN is a Cisco technology that secures IP multicast and unicast traffic across a wide area network using a shared security association rather than point-to-point tunnels.
Key term
LDP Protocol
LDP, or Label Distribution Protocol, is a protocol that routers use to automatically exchange labels that enable MPLS (Multiprotocol Label Switching) to create fast, efficient paths for data packets across a network.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.