exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 68 discussion

Actual exam question from Cisco's 350-701
Question #: 68
Topic #: 1
[All 350-701 Questions]

A network engineer needs to select a VPN type that provides the most stringent security, multiple security associations for the connections, and efficient VPN establishment with the least bandwidth consumption. Why should the engineer select either FlexVPN or DMVPN for this environment?

  • A. DMVPN because it uses multiple SAs and FlexVPN does not.
  • B. DMVPN because it supports IKEv2 and FlexVPN does not.
  • C. FlexVPN because it supports IKEv2 and DMVPN does not.
  • D. FlexVPN because it uses multiple SAs and DMVPN does not.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Smileebloke
Highly Voted 3 years ago
IKEv2 Multi-SA The IKEv2 Multi-SA feature allows an IKEv2 Dynamic Virtual Tunnel Interface (DVTI) session on the IKEv2 responder to support multiple IPsec Security Associations (SA). The maximum number of IPsec SAs per DVTI session is either obtained from AAA authorization or configured on the IPsec profile. The value from AAA has a higher priority. Any change to the max-flow-limit argument in the IPsec profile is not applied to the current session but is applied to subsequent sessions. The IKEv2 Multi-SA feature makes the configuration of the IKEv2 profile in the IPsec profile optional. This optional configuration allows IPsec DVTI sessions using the same virtual template to have different IKEv2 profiles, thus saving the number of virtual template configurations. Note The IKEv2 Multi-SA feature allows multiple IPsec SAs that have non-any-any proxies. However, when the IPsec SA proxies are any-any, a single IPsec SA is allowed. For more information, see the “Multi-SA Support for Dynamic Virtual Tunnel Interfaces for IKEv2” module in the Security for VPNs with IPsec Configuration Guide.
upvoted 6 times
...
willroute
Most Recent 6 months ago
Tricky question, as DMVPN can do it with sharing ipsec tunnel, so both can do it, but most logical is D....Cisco style question. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-share-ipsec-w-tun-protect.html#:~:text=Glossary%20Close-,Sharing%20IPsec%20with%20Tunnel%20Protection,results%20in%20network%20connectivity%20problems.&text=Security%20threats%20and%20the%20cryptographic,Encryption%20(NGE)%20white%20paper.
upvoted 1 times
...
Nonono2
10 months, 2 weeks ago
Selected Answer: C
The answer is C
upvoted 1 times
...
jku2cya
1 year, 10 months ago
Selected Answer: D
DMVPN can be configured with IKEv2, so answer is not C. I wasn't able to find Cisco documentation to back this up, but found this configuration example: https://journey2theccie.wordpress.com/2020/03/13/ikev1-ikev2-configuration-in-dmvpn/
upvoted 3 times
...
alexyozgat24
2 years ago
Really like the comment on following link for this discussion, per say- it looks like Answer is C https://community.cisco.com/t5/network-security/what-is-the-difference-between-dmvpn-and-flexvpn/td-p/3438913
upvoted 1 times
...
psuoh
2 years, 4 months ago
What is the difference between FlexVPN and DMVPN? IPSec: One key difference between FlexVPN and default Dynamic Multipoint VPN (DMVPN) is the protocol used for negotiating IPsec Security Associations (SAs). While DMVPN defaults to using Internet Key Exchange version 1 (IKEv1), FlexVPN utilizes IKEv2.
upvoted 2 times
psuoh
2 years, 4 months ago
ANswer is C
upvoted 1 times
johnnybgud
2 years, 4 months ago
But DMVPN definitely support IKEv2, and Answer C says "...DMVPN does not". Therefore answer is likely D.
upvoted 4 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago