exam questions

Exam 400-007 All Questions

View all questions & answers for the 400-007 exam

Exam 400-007 topic 1 question 274 discussion

Actual exam question from Cisco's 400-007
Question #: 274
Topic #: 1
[All 400-007 Questions]

Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The Info-Sec team has suggested to isolate production traffic end-to-end with an encryption over the transport network to comply with the HIPAA standard. Which solution must be used in their design if Company XYZ wants a quick roll out?

  • A. A firewall can be placed centrally to filter out the traffic based on required ports.
  • B. VRF-Lite can be implemented toward the downstream network and VRF-based tunnels combined with IPsec can be implemented over the service provider
  • C. GETVPN can be implemented over the MPLS provider, which provides a payload encryption without the overhead of the tunnelling
  • D. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and encrypted packet end-to-end
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sandccie
2 months ago
Selected Answer: D
D. firewall nor VRF provide data encryption. GETVPN does not support point-to-point links. IPSec tunnels support encryption over MPLS and point-to-point links.
upvoted 1 times
sandccie
2 months ago
C. sorry for incorrect statements. The answer is GETVPN.
upvoted 1 times
...
...
kalulosu
3 months, 2 weeks ago
Selected Answer: C
Answer is c. GETVPN provides payload encryption without tunneling overhead, enabling rapid deployment and efficient traffic isolation over MPLS providers.
upvoted 1 times
...
krabogi
6 months, 2 weeks ago
Selected Answer: D
The requirement is for end-to-end production traffic encryption, hence all the links. C covers only MPLS links.
upvoted 2 times
...
Doobiedoo
8 months, 3 weeks ago
Selected Answer: D
D. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and encrypted packet end-to-end. Here's why: * IPsec: This is a well-established standard for providing secure, encrypted communication over IP networks. It offers a variety of modes (transport, tunnel) and algorithms to meet different security needs. * Point-to-point tunnels: Creating point-to-point tunnels between production units and marketing departments ensures that traffic remains isolated and encrypted throughout its journey, even over the MPLS network. * Quick rollout: IPsec is widely supported by network devices, making it relatively straightforward to implement and deploy. While other options might provide some level of security, they may require more complex configurations or additional hardware (for GETVPN), which could delay the rollout process. IPsec point-to-point tunnels offer a practical and efficient solution for Company XYZ to meet their security and compliance requirements.
upvoted 1 times
...
famov66542
12 months ago
Selected Answer: C
While other options could technically work, they may involve more complexity or overhead: * A firewall does not provide end-to-end encryption. * VRF-Lite with IPsec adds more complexity and overhead, which may not be suitable for a quick rollout. * IPsec point-to-point tunnels introduce significant overhead and complexity, particularly across a large and dispersed network. Thus, GETVPN is the optimal choice for a quick and efficient implementation.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago