Courseiva
Security →easyMultiple Choice

CCNP Security Practice Question

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that installing a valid certificate is sufficient, while overlooking that the IKEv2 profile must explicitly point to the trustpoint for authentication to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IKEv2 profile is not referencing the correct trustpoint for certificate authentication.

For IKEv2 certificate-based authentication, the IKEv2 profile must reference a trustpoint that contains the router's identity certificate and the CA certificate to validate peer certificates. If the trustpoint is missing or incorrect, the router cannot authenticate the client's certificate, resulting in failure. Ensuring the correct trustpoint is referenced and that the CA chain is complete resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pre-shared key is not configured on the IKEv2 profile.

    Why it's wrong here

    The scenario specifies certificate-based authentication, so a pre-shared key is not used. Configuring a pre-shared key would be irrelevant and would not resolve the certificate authentication failure. The error is specifically about certificate authentication, so the issue lies in the PKI configuration, not in pre-shared key settings.

  • ✗

    The remote clients are using IKEv1 instead of IKEv2.

    Why it's wrong here

    If clients used IKEv1, the router might not have a matching policy, but the error message specifically mentions IKEv2 certificate authentication failed, indicating an IKEv2 negotiation attempt. The failure is within IKEv2 processing, so the client version mismatch is not the cause. The issue is more likely the trustpoint reference in the IKEv2 profile.

  • ✗

    The router's certificate has expired.

    Why it's wrong here

    An expired certificate would cause authentication failure, but the scenario states a valid identity certificate is installed. While expiration is a common issue, the question specifies the certificate is valid, so expiration is not the likely cause. The failure is more likely due to a trustpoint or CA configuration issue, such as the router not trusting the CA that issued the client certificates.

  • ✓

    The IKEv2 profile is not referencing the correct trustpoint for certificate authentication.

    Why this is correct

    In IKEv2, the profile must specify the trustpoint that contains the router's identity certificate and the CA certificate for verifying peer certificates. If the trustpoint is not referenced or is incorrect, the router cannot validate client certificates, leading to authentication failure. This is a common misconfiguration when setting up certificate-based IKEv2. The logs indicating certificate authentication failed point to a trustpoint or PKI issue.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.