Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network engineer is configuring IPsec site-to-site VPNs on a Cisco IOS XE router. The design requires that the router authenticate peers using certificates issued by an internal PKI rather than pre-shared keys, and that IKEv2 be used for the key exchange. Which configuration element is required to support certificate-based authentication for IKEv2 on this router?

⚠ Common exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 profile configuration, when IKEv2 certificate authentication depends on a trustpoint referenced in the IKEv2 profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A crypto pki trustpoint configuration with enrollment and an RSA key pair, referenced in the IKEv2 profile.

IKEv2 certificate authentication requires an enrolled PKI trustpoint, an RSA key pair, and an IKEv2 profile that references RSA signature authentication with that trustpoint. Pre-shared keys and ISAKMP policies belong to the alternative authentication method or the older IKEv1 framework, and a crypto map only defines IPsec policy and peer identity. The trustpoint is the essential element enabling certificate-based peer authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A pre-shared key configured under the IKEv2 keyring with the peer's address.

    Why it's wrong here

    A pre-shared key is the alternative authentication method that the design explicitly replaces with certificates. Configuring a keyring with a PSK would not enable certificate authentication and would contradict the requirement to use the internal PKI. IKEv2 keyrings can still exist for other peers, but for this scenario the peer must be authenticated by certificate, so a PSK does not satisfy the design.

  • ✗

    An ISAKMP policy with authentication pre-share under the crypto isakmp configuration.

    Why it's wrong here

    ISAKMP policy configuration applies to IKEv1, not IKEv2. IKEv2 uses IKEv2 profiles and proposals rather than the older crypto isakmp policy syntax. Even if this were an IKEv1 deployment, specifying pre-share authentication would contradict the certificate requirement. This option is both the wrong IKE version and the wrong authentication method for the stated design.

  • ✓

    A crypto pki trustpoint configuration with enrollment and an RSA key pair, referenced in the IKEv2 profile.

    Why this is correct

    Certificate-based IKEv2 authentication requires a trustpoint that defines the CA, an enrolled identity certificate, and an RSA key pair on the router. The IKEv2 profile then references authentication local rsa-sig and the trustpoint so the router can present its certificate and validate the peer's certificate chain. Without a properly enrolled trustpoint, the router cannot perform RSA signature authentication, so this element is mandatory for the design.

  • ✗

    A crypto map with the set peer command specifying the remote peer's hostname.

    Why it's wrong here

    The crypto map defines the IPsec policy and identifies the remote peer, but it does not provide certificate authentication. Specifying the peer by hostname affects identity matching, not trust establishment. Certificate authentication depends on the trustpoint and IKEv2 profile authentication settings, so a crypto map alone cannot satisfy the requirement to authenticate peers through the internal PKI.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.