Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is deploying a GET VPN solution across an MPLS VPN WAN. The group members must encrypt traffic between any pair of sites without establishing point-to-point tunnels, and the key server must distribute a common encryption policy to all members. The engineer has configured the key server with a rekey policy but group members are not receiving rekeys. Which action must be taken on the key server to enable successful rekey transmission?

⚠ Common exam trap

The trap here is assuming that rekey delivery is always multicast and that multicast is available on all transport networks, when in fact unicast rekey may be required for non-multicast-capable underlays.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable unicast rekey on the key server so that rekeys are sent directly to each group member.

GET VPN key servers typically send rekeys using multicast to the group address. In networks that do not support multicast or where multicast is not enabled on the transport, group members will not receive rekeys. Enabling unicast rekey on the key server forces rekeys to be sent directly to each registered group member's unicast address, ensuring they receive the updated policy. This is a standard configuration adjustment for non-multicast underlays.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the key server to use a different group identity (GDOI group ID) that matches the members.

    Why it's wrong here

    The group identity must match between key server and group members for them to join the group and receive rekeys. However, if members are not receiving rekeys, the group identity is likely already correct because they would not have registered otherwise. Changing it would break existing registrations and is not the appropriate fix for rekey delivery.

  • ✗

    Configure the group members with the rekey retransmit timer set to a lower value.

    Why it's wrong here

    The rekey retransmit timer on group members controls how often they retransmit rekey acknowledgments if they are not received by the key server. It does not affect the initial reception of rekeys. Lowering this timer would not solve the problem of members not receiving rekeys at all; it only affects reliability after a rekey is received.

  • ✗

    Configure the key server to use IKEv2 for rekey authentication instead of IKEv1.

    Why it's wrong here

    GET VPN rekey authentication uses either the GDOI protocol or IKEv1 phase 1, not IKEv2. Changing to IKEv2 will not enable rekey delivery because group members expect GDOI or IKEv1-based rekey messages. The failure is not related to the IKE version; the issue is likely a missing unicast rekey configuration or incorrect group identity.

  • ✓

    Enable unicast rekey on the key server so that rekeys are sent directly to each group member.

    Why this is correct

    By default, GET VPN key servers send rekeys via multicast to the group address. If the underlay network does not support multicast or the group members are not receiving multicast rekeys, enabling unicast rekey ensures each member receives the rekey directly. This is a common requirement in MPLS VPN or non-multicast-capable transport networks.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.