Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?

⚠ Common exam trap

The trap here is assuming that any key-distribution need is solved by IKE, when GET VPN specifically relies on GDOI for group key and rekey delivery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group Domain of Interpretation (GDOI)

GET VPN uses the Group Domain of Interpretation so that a key server can distribute a shared Group Security Association and push rekey messages to all group members. Members register with the key server, obtain the same keys and policies, and then encrypt traffic directly with one another over the provider network without building point-to-point tunnels. This preserves the any-to-any model and keeps rekeying centralized on the key server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IKEv2 with a hub-and-spoke profile on the key server

    Why it's wrong here

    IKEv2 negotiates per-peer SAs and is designed for point-to-point tunnel establishment between two peers. In a GET VPN design, group members do not run IKE with each other or with the key server for data traffic; they share a common Group Security Association. Using IKEv2 here would create per-tunnel SAs and defeat the any-to-any tunnel-less model that the key server's rekey mechanism is built to support.

  • ✓

    Group Domain of Interpretation (GDOI)

    Why this is correct

    GDOI is the protocol the key server uses in GET VPN to distribute the Group Security Association, including the rekey messages carrying updated keys and policies. Group members register with the key server over GDOI, receive the shared keys, and then encrypt traffic directly between themselves without per-pair tunnels. This matches the requirement for identical keys pushed from a single key server.

  • ✗

    IPsec SA negotiation using ISAKMP aggressive mode

    Why it's wrong here

    Aggressive mode is an IKEv1 Phase 1 exchange used to speed up peer authentication, typically for remote-access clients with dynamic addresses. It negotiates pairwise IKE and IPsec SAs and does not implement group key distribution. GET VPN requires a Group Security Association shared by all members, which aggressive mode cannot supply, so this would not satisfy the identical-key requirement.

  • ✗

    NHRP with a next-hop server mapping

    Why it's wrong here

    NHRP is the resolution protocol used by DMVPN to map tunnel addresses to NBMA addresses so spokes can build on-demand tunnels. It does not distribute encryption keys and has no rekey message format. Deploying NHRP in a GET VPN design would not provide the Group Security Association or the periodic rekey push the key server must deliver to every group member.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.