Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?

⚠ Common exam trap

The trap here is focusing on IKE or NAT details while overlooking that the crypto map must be applied to an interface to become operational.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the crypto map to the outbound interface using the crypto map command under interface configuration.

The crypto map defines the IPsec policy and must be applied to the outbound interface facing the remote peer. This application is what causes the router to inspect outbound packets, match the ACL, and initiate the IPsec tunnel. Other elements like ISAKMP policies and static routes are supporting configurations but do not activate the crypto map.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a static route to the remote peer's public IP address pointing to the next-hop router.

    Why it's wrong here

    A static route to the peer may be necessary for reachability, but it is not the configuration that activates the crypto map or determines which traffic is encrypted. The crypto map must be applied to an interface to process interesting traffic. The question asks for the additional configuration to apply the crypto map and establish the tunnel, not just routing.

  • ✗

    Enable NAT on the interface to translate the private subnet to a public address before encryption.

    Why it's wrong here

    NAT and IPsec can coexist, but NAT is not required to apply the crypto map or establish the tunnel. In fact, if NAT is applied to traffic that should be encrypted, it can break IPsec unless NAT-T or proper ordering is configured. The question focuses on applying the crypto map, not on address translation.

  • ✗

    Configure an ISAKMP policy with a matching pre-shared key on both peers.

    Why it's wrong here

    An ISAKMP policy and pre-shared key are required for IKE phase 1, but they do not apply the crypto map to an interface. The crypto map itself contains the peer, transform set, and ACL, and must be applied to an interface to become active. Without interface application, the tunnel will not initiate even if ISAKMP is correctly configured.

  • ✓

    Apply the crypto map to the outbound interface using the crypto map command under interface configuration.

    Why this is correct

    The crypto map must be applied to the interface that sends traffic to the remote peer, typically the WAN interface, using the crypto map <name> command. This enables the router to evaluate outbound packets against the ACL, match interesting traffic, and initiate the IPsec tunnel. Without applying the crypto map to an interface, the VPN configuration remains inactive.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.