hardMultiple Choice
350-401 Practice Question: Is configuring a GETVPN solution for a large…
A network engineer is configuring a GETVPN solution for a large enterprise with many remote sites. The engineer wants to ensure that all traffic between sites is encrypted using a common group key. The key server (KS) is a Cisco ASR 1000. After configuration, the group members (GMs) can register with the KS, but traffic between GMs is not encrypted. The engineer checks the KS configuration and sees that the crypto gdoi group has been defined with a transform set and a security association. What is the most likely missing configuration?
⚠ Common exam trap
Cisco often tests the misconception that a transform set and SA alone are sufficient for encryption, but in GETVPN the traffic selector (ACL) is mandatory and must be defined on the KS to be pushed to GMs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KS is missing an access list to define the traffic to encrypt.
In GETVPN, the Key Server (KS) distributes the common group key, but the actual encryption of traffic between Group Members (GMs) is controlled by an access list (ACL) that defines which traffic should be encrypted. Without this ACL on the KS, the GMs receive the key but have no policy specifying which packets to encrypt, so traffic between GMs remains unencrypted. The correct configuration requires an ACL under the crypto gdoi group to identify the protected traffic (e.g., permit ip 10.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The KS is missing an access list to define the traffic to encrypt.
Why this is correct
In GETVPN, the key server (KS) defines which traffic is encrypted by creating a group policy that includes an extended access-list as the traffic selector. If this ACL is missing, the KS has no 'interesting traffic' to bind to the GDOI security association, so even though GMs may register successfully, they receive no encryption policy. As a result, no traffic is encrypted between GMs.
- ✗
The group name on the GMs does not match the KS.
Why it's wrong here
Group members (GMs) and the key server communicate using a shared group identifier that is configured as the group name. If the GM's group name does not exactly match the KS's configured group name, the GDOI registration request is rejected, and the GM never receives the group key material. Therefore, the failure would occur during the initial registration phase, not as a one-way traffic issue.
- ✗
The KS is not configured with an IPsec profile.
Why it's wrong here
GETVPN does not rely on legacy IPsec profiles, which are used for crypto map or IPsec VTI configurations to define transform sets and peer settings. Instead, GETVPN uses the GDOI protocol (UDP 848) to distribute a single group SAs from the KS to all GMs. An IPsec profile is simply not part of GDOI design, so its absence has no effect on GETVPN operation.
- ✗
The GMs are in different IP subnets than the KS.
Why it's wrong here
GETVPN is designed as an overlay within a dynamic network, and it does not require GMs and the KS to reside in the same IP subnet. Group members can be distributed across any routed IP network as long as they can reach the KS's IP address for GDOI registration. In fact, typical deployments place the KS in a central location while GMs are on remote branches in separate subnets, so this is an expected and fully supported configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.