Courseiva
Security →easyMultiple Choice

CCNP Security Practice Question

A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?

⚠ Common exam trap

Candidates often confuse the command that binds a trustpoint to an IKEv2 profile with the command that matches certificate fields or configures PSK authentication, leading to an incomplete or incorrect configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.

IKEv2 certificate-based authentication requires a PKI trustpoint to be associated with the IKEv2 profile. The 'pki trustpoint' command under the IKEv2 profile binds the trustpoint, enabling the router to use certificates for authentication. This must be configured on both peers. Other commands like 'match certificate' are used for certificate map matching, and keyrings are for PSK authentication, neither of which satisfies the certificate requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    crypto ikev2 proposal <name> and then encryption aes-cbc-256 under the proposal.

    Why it's wrong here

    The 'crypto ikev2 proposal' command defines the encryption, integrity, and Diffie-Hellman group parameters for the IKEv2 SA. It does not handle authentication or trustpoint selection. While a proposal is necessary for IKEv2, it does not specify how peers authenticate, so it cannot fulfill the certificate-based authentication requirement.

  • ✓

    crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.

    Why this is correct

    Within an IKEv2 profile, the 'pki trustpoint' command specifies which PKI trustpoint the router will use for certificate-based authentication. This is the correct way to bind a trustpoint to an IKEv2 profile. Both routers must have this configured to present and validate certificates during IKEv2 negotiation, satisfying the certificate-based authentication requirement.

  • ✗

    crypto ikev2 profile <name> and then match certificate <map-name> under the profile.

    Why it's wrong here

    The 'match certificate' command under an IKEv2 profile is used for certificate map matching, which allows the router to select a trustpoint based on certificate fields. However, it does not directly specify the trustpoint for authentication. The trustpoint itself must be referenced using the 'identity local dn' or 'pki trustpoint' command within the profile, making this option incomplete for the requirement.

  • ✗

    crypto ikev2 keyring <name> and then pre-shared-key <key> under the keyring.

    Why it's wrong here

    The 'crypto ikev2 keyring' and 'pre-shared-key' commands configure pre-shared key authentication, not certificate-based authentication. While keyrings are used in IKEv2 for PSK authentication, the scenario explicitly requires certificate-based authentication. Using a keyring would not meet the security policy and would leave the VPN using a less secure authentication method.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.