Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?

⚠ Common exam trap

Candidates often confuse rsa-sig with rsa-encr; rsa-sig uses digital certificates for authentication, while rsa-encr uses RSA encrypted nonces without certificates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

authentication rsa-sig

In an ISAKMP policy for IKEv1, the 'authentication rsa-sig' command enables RSA signature authentication, which relies on digital certificates. The other options are incorrect: pre-share uses pre-shared keys, rsa-encr uses encrypted nonces, and eap is used for EAP authentication, typically in IKEv2. The policy requires certificate-based authentication, so rsa-sig is the correct command.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    authentication rsa-sig

    Why this is correct

    The 'authentication rsa-sig' command within the ISAKMP policy specifies that RSA signatures should be used for authentication. This means the router will use digital certificates obtained from a CA to authenticate peers. This matches the requirement to use digital certificates issued by a corporate PKI. The command is configured under 'crypto isakmp policy' configuration mode.

  • ✗

    authentication rsa-encr

    Why it's wrong here

    The 'authentication rsa-encr' command is used for RSA encrypted nonces, which is a legacy authentication method that uses RSA keys to encrypt a nonce. It does not use digital certificates. This method is rarely used today and does not satisfy the requirement for certificate-based authentication. It is also not supported in all IOS versions.

  • ✗

    authentication eap

    Why it's wrong here

    The 'authentication eap' command is used for Extensible Authentication Protocol authentication, often in conjunction with IKEv2 and EAP methods like EAP-TLS. While EAP can use digital certificates, it is not the direct command for RSA signature authentication in an ISAKMP policy for IKEv1. The scenario implies IKEv1 with ISAKMP policy, where rsa-sig is the correct choice.

  • ✗

    authentication pre-share

    Why it's wrong here

    The 'authentication pre-share' command configures the ISAKMP policy to use pre-shared keys for authentication, which does not meet the requirement for digital certificates. Pre-shared keys are simpler but less secure and do not scale well. This command would override the need for a PKI and is not suitable when the policy mandates certificate-based authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.