CCNP Security Practice Question
A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?
⚠ Common exam trap
Candidates often confuse rsa-sig with rsa-encr; rsa-sig uses digital certificates for authentication, while rsa-encr uses RSA encrypted nonces without certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authentication rsa-sig
In an ISAKMP policy for IKEv1, the 'authentication rsa-sig' command enables RSA signature authentication, which relies on digital certificates. The other options are incorrect: pre-share uses pre-shared keys, rsa-encr uses encrypted nonces, and eap is used for EAP authentication, typically in IKEv2. The policy requires certificate-based authentication, so rsa-sig is the correct command.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
authentication rsa-sig
Why this is correct
The 'authentication rsa-sig' command within the ISAKMP policy specifies that RSA signatures should be used for authentication. This means the router will use digital certificates obtained from a CA to authenticate peers. This matches the requirement to use digital certificates issued by a corporate PKI. The command is configured under 'crypto isakmp policy' configuration mode.
- ✗
authentication rsa-encr
Why it's wrong here
The 'authentication rsa-encr' command is used for RSA encrypted nonces, which is a legacy authentication method that uses RSA keys to encrypt a nonce. It does not use digital certificates. This method is rarely used today and does not satisfy the requirement for certificate-based authentication. It is also not supported in all IOS versions.
- ✗
authentication eap
Why it's wrong here
The 'authentication eap' command is used for Extensible Authentication Protocol authentication, often in conjunction with IKEv2 and EAP methods like EAP-TLS. While EAP can use digital certificates, it is not the direct command for RSA signature authentication in an ISAKMP policy for IKEv1. The scenario implies IKEv1 with ISAKMP policy, where rsa-sig is the correct choice.
- ✗
authentication pre-share
Why it's wrong here
The 'authentication pre-share' command configures the ISAKMP policy to use pre-shared keys for authentication, which does not meet the requirement for digital certificates. Pre-shared keys are simpler but less secure and do not scale well. This command would override the need for a PKI and is not suitable when the policy mandates certificate-based authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.