GETVPN vs IPsec for HIPAA Compliance

Answer Correct answer: C — GETVPN can be implemented over the MPLS provider, which provides a payload encryption without the overhead of the tunnelling.

Company XYZ has multiple production units and marketing departments across the region. The current network is a mixture of point-to-point links and MPLS Layer 3 VPN service from the provider. The Info-Sec team has suggested to isolate production traffic end-to-end with an encryption over the transport network to comply with the HIPAA standard. Which solution must be used in their design if Company XYZ wants a quick roll out?

  1. A firewall can be placed centrally to filter out the traffic based on required ports.
  2. VRF-Lite can be implemented toward the downstream network and VRF-based tunnels combined with IPsec can be implemented over the service provider
  3. GETVPN can be implemented over the MPLS provider, which provides a payload encryption without the overhead of the tunnelling Correct Answer
  4. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and encrypted packet end-to-end

Community Votes

C
56%
D
44%

56% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the specific advantages of Group Encrypted Transport VPN (GETVPN) over traditional IPsec in large-scale provider networks, focusing on overhead and scalability.

This question evaluates the trade-offs between GETVPN and IPsec for encrypting traffic over MPLS and point-to-point links. The correct solution prioritizes rapid deployment and payload encryption efficiency.

Many candidates choose D (IPsec) because it is the standard for end-to-end encryption, overlooking the explicit requirement for a 'quick roll out' and the elimination of tunneling overhead.

Community Discussion (5 comments)

sandccie 👍 1 Selected: D
D. firewall nor VRF provide data encryption. GETVPN does not support point-to-point links. IPSec tunnels support encryption over MPLS and point-to-point links.
kalulosu 👍 1 Selected: C
Answer is c. GETVPN provides payload encryption without tunneling overhead, enabling rapid deployment and efficient traffic isolation over MPLS providers.
krabogi 👍 2 Selected: D
The requirement is for end-to-end production traffic encryption, hence all the links. C covers only MPLS links.
Doobiedoo 👍 1 Selected: D
D. IPsec point-to-point tunnels over the MPLS and point-to-point links provide an isolated and encrypted packet end-to-end. Here's why: IPsec: This is a well-established standard for providing secure, encrypted communication over IP networks. It offers a variety of modes (transport, tunnel) and algorithms to meet different security needs. Point-to-point tunnels: Creating point-to-point tunnels between production units and marketing departments ensures that traffic remains isolated and encrypted throughout its journey, even over the MPLS network. * Quick rollout: IPsec is widely supported by network devices, making it relatively straightforward to implement and deploy. While other options might provide some level of security, they may require more complex configurations or additional hardware (for GETVPN), which could delay the rollout process. IPsec point-to-point tunnels offer a practical and efficient solution for Company XYZ to meet their security and compliance requirements.
famov66542 👍 4 Selected: C
While other options could technically work, they may involve more complexity or overhead: A firewall does not provide end-to-end encryption. VRF-Lite with IPsec adds more complexity and overhead, which may not be suitable for a quick rollout. * IPsec point-to-point tunnels introduce significant overhead and complexity, particularly across a large and dispersed network. Thus, GETVPN is the optimal choice for a quick and efficient implementation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario requires isolating production traffic with encryption across both MPLS and point-to-point links while ensuring a quick rollout. GETVPN (Group Encrypted Transport VPN) is designed specifically for this purpose within an MPLS infrastructure. It provides payload encryption directly to the destination without encapsulating packets in a tunnel header, significantly reducing overhead. This architecture allows for faster deployment and better scalability compared to individual site-to-site tunnels.

Why the Other Options Are Wrong

Option A is incorrect because a central firewall does not provide end-to-end encryption; it only filters traffic at a single point. Option B (VRF-Lite with IPsec) involves significant complexity due to the need for managing multiple VRFs and individual IPsec tunnels, which contradicts the 'quick roll out' requirement. Option D (IPsec point-to-point tunnels) is the most common distractor; while it provides encryption, establishing individual tunnels for every site pair creates high management overhead and latency, making it slower to deploy than GETVPN.

Community Comment Notes

Community feedback is split between C and D. Some users argue that GETVPN is superior because it avoids tunneling overhead, facilitating rapid deployment. Others contend that IPsec is necessary for true end-to-end coverage, especially if the network includes non-MPLS links. However, the exam logic favors the solution that best meets the 'quick roll out' constraint through efficiency.

Official Reference

Exam Strategy

When an exam question emphasizes 'quick roll out' or 'scalability' in a service provider environment, look for solutions that minimize per-packet processing overhead. GETVPN is the key technology for optimizing IPsec-like security without the tunneling penalty.

Frequently Asked Questions

Why is GETVPN preferred over IPsec for quick rollout?

GETVPN encrypts payloads directly without creating separate tunnels, reducing overhead and simplifying deployment across large networks.

Does GETVPN support point-to-point links?

GETVPN is primarily designed for MPLS-based service provider networks. For pure point-to-point links outside the MPLS domain, other methods might be needed, but GETVPN is the optimal choice for the described mixed environment's core requirements.

Related Analysis

← Back to 400-007 Study Guide