AES-CBC for Multicast in Cisco SD-WAN (GCM for Unicast)

Describe Cisco SD-WAN design considerations (control plane design, overlay design, LAN design, high availability, redundancy, scalability, security design, QoS and multicast over SD-WAN fabric)
Answer Correct answer: C — For multicast, SD-WAN uses AES-CBC with HMAC; GCM is preferred for unicast but its counter mode does not suit multicast.

Which AES mode should be used in a Cisco SD-WAN environment that includes multicast applications?

  1. Electronic Code Book (ECB)
  2. Cipher Feedback (CFB)
  3. Cipher Block Chaining (CBC) Correct Answer
  4. Galois/Counter Mode (GCM)

Community Votes

D
50%
C
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Multicast -> CBC (with HMAC); unicast -> GCM. The question's 'includes multicast applications' keyword is what selects CBC over the otherwise-preferred GCM.

Cisco SD-WAN prefers AES-256-GCM for unicast encryption, but for multicast applications it uses AES-CBC with an HMAC because GCM's counter/nonce handling does not fit multicast distribution. Newer releases use GCM for unicast; CBC remains the multicast mode.

Picking D (GCM): GCM is the preferred general mode but it does not handle multicast well; the question explicitly mentions multicast, which is the cue to choose CBC.

Community Discussion (3 comments)

34da117 👍 2 Selected: C
2024 CCNP Enterprise Design ENSLD Anthony Bruno, Steve Jordan.pdf page368 .... such as in multicast app
Fibzy 👍 2
Correct answer is D. "vEdge routers use Advanced Encryption Standard (AES) with a 256-bit key length with the preferred operation Galois/Counter" FROM OCG Mode (GCM)—hence AES-256-GCM. A secondary mode, cipher block chaining (CBC), can be used when required, such as in multicast applications.
26d13e9 👍 2 Selected: D
According to the below link, it depends on the SD-WAN release...go figure....so C and D I guess are both correct in a way or the other.....but will go with D since in C its a combination of CBC and HMAC For multicast traffic: Cisco SD-WAN Release 20.1.x and later– the encryption algorithm is AES-256-GCM Previous releases– the encryption algorithm is AES-256-CBC with SHA1-HMAC https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/vedge-20-x/security-book/config-sec-param.html#:~:text=For%20unicast%20traffic%2C%20the%20encryption,algorithm%20is%20AES%2D256%2DGCM

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C is correct. Cisco SD-WAN uses AES-256-GCM as the preferred mode for unicast, but for multicast applications it falls back to AES-CBC with an HMAC, because GCM's counter/nonce design does not suit multicast distribution.

Why the Other Options Are Wrong

A (ECB) and B (CFB) are not the SD-WAN encryption modes. D (GCM) is the general preferred mode but is unsuited to multicast, which is exactly the condition the question states.

Community Comment Notes

The vote is split D (50) vs C (50). The OCG and Cisco docs note GCM is preferred, with CBC used 'when required, such as in multicast applications,' so the multicast keyword selects C.

Official Reference

Related Analysis

Practice All 300-420 Questions

Access 150 questions with complete answers and detailed explanations.

View Full 300-420 Practice Test →

← Back to 300-420 Study Guide