CCNP Infrastructure Practice Question
A network engineer is configuring a GRE tunnel between two sites to transport IPv6 traffic over an IPv4-only underlay. The engineer wants to ensure that the tunnel interface supports IPv6 and that traffic is encrypted. Which technology should be combined with GRE to provide encryption?
⚠ Common exam trap
A common mix-up: candidates confuse IPsec transport mode with tunnel mode; transport mode does not encrypt the GRE header, so it is not appropriate for protecting GRE tunnels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPsec in tunnel mode
To encrypt a GRE tunnel, IPsec in tunnel mode is used. It encrypts the entire original packet, including the GRE header, and encapsulates it in a new IPsec packet. This provides confidentiality and integrity for the tunneled traffic. Transport mode does not encapsulate the original packet, MACsec is Layer 2 only, and TLS is application-layer, so they are not suitable for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IPsec in tunnel mode
Why this is correct
IPsec in tunnel mode encrypts the entire original IP packet, including the GRE header and payload, and encapsulates it within a new IPsec packet. This provides confidentiality and integrity for the GRE tunnel, making it suitable for transporting IPv6 over an IPv4 underlay securely. It is the standard method for protecting GRE tunnels.
- ✗
MACsec
Why it's wrong here
MACsec operates at Layer 2 and provides encryption for Ethernet frames on a hop-by-hop basis. It cannot be used to encrypt GRE tunnels that traverse a Layer 3 network. MACsec is typically used on point-to-point Ethernet links, not for end-to-end tunnel encryption over an IP underlay.
- ✗
TLS
Why it's wrong here
TLS is an application-layer protocol used to secure applications like HTTPS, not for encrypting IP tunnels. While it can encrypt data in transit, it does not provide the necessary encapsulation and is not used to protect GRE tunnels. GRE tunnels require a network-layer encryption mechanism like IPsec.
- ✗
IPsec in transport mode
Why it's wrong here
IPsec in transport mode only encrypts the payload of the original IP packet and does not encapsulate it. When combined with GRE, transport mode would encrypt the GRE payload but not the GRE header itself, which may not provide the necessary security for the tunnel. Additionally, transport mode is typically used for end-to-end communication, not for tunnel protection.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.