Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is deploying GET VPN across an MPLS L3VPN service provider network. The key server is reachable by all group members, and the engineer wants to avoid rekeying storms when many group members reboot simultaneously after a power outage. Which mechanism should the engineer configure on the key server to spread rekey retransmissions over a period of time?

⚠ Common exam trap

The trap here is assuming that disabling rekey acknowledgment reduces load, when in fact acknowledgment is the mechanism that lets the key server retransmit missing rekeys reliably.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the key server with a rekey retransmit interval and a retransmit limit, and enable the rekey acknowledgment feature so members request unicast retransmissions.

The key server in GET VPN distributes the group key via multicast and then uses reliable rekey retransmission with acknowledgment to unicast the rekey to members that did not receive it. Configuring a retransmit interval and retransmit limit spreads those unicast retransmissions over time, so a large number of members rebooting simultaneously do not overload the key server. This preserves key synchronization across the group without disabling the reliability mechanism that guarantees delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the key server with a rekey retransmit interval and a retransmit limit, and enable the rekey acknowledgment feature so members request unicast retransmissions.

    Why this is correct

    GET VPN rekey retransmission with acknowledgment lets the key server pace unicast retransmissions to members that did not receive the multicast rekey. When a large number of group members reboot together, the key server sends the multicast rekey, then retransmits at the configured interval to non-responding members, up to the retransmit limit. This prevents an overload of simultaneous unicast rekeys while still guaranteeing key delivery.

  • ✗

    Configure the key server with a rekey retransmit interval and disable the rekey acknowledgment, forcing members to pull rekeys at randomized intervals.

    Why it's wrong here

    Disabling rekey acknowledgment removes the reliable unicast delivery of the rekey, which is what makes GET VPN rekey distribution resilient. Without acknowledgments, members that miss a multicast rekey have no way to request a retransmission, so some devices keep stale keys and traffic fails. Randomized pull intervals are also not how the key server paces retransmissions, so this does not solve the simultaneous-reboot problem.

  • ✗

    Configure the group members with a longer registration timeout so they wait longer before contacting the key server after reboot.

    Why it's wrong here

    The registration timeout controls how long a member waits for a registration response, not how long it delays before sending its initial registration. Extending it does not stagger the reboot-time registration or rekey requests, and it can slow failure detection. Pacing of rekey retransmissions is controlled on the key server, so changing a member-side timer does not address the stated problem.

  • ✗

    Configure the key server to use a shorter rekey lifetime so that keys expire quickly and members are forced to re-register frequently.

    Why it's wrong here

    Shortening the rekey lifetime makes keys expire faster, which increases the frequency of rekey distribution and worsens the load on the key server and network. It does not spread retransmissions over time after a mass reboot, and frequent re-registration adds control-plane churn. The rekey lifetime is a security parameter, not a mechanism for pacing retransmissions to many members at once.

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.