CCNP Security Practice Question
A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?
⚠ Common exam trap
The trap here is focusing on IKE or NAT details while overlooking that the crypto map must be applied to an interface to become operational.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the crypto map to the outbound interface using the crypto map command under interface configuration.
The crypto map defines the IPsec policy and must be applied to the outbound interface facing the remote peer. This application is what causes the router to inspect outbound packets, match the ACL, and initiate the IPsec tunnel. Other elements like ISAKMP policies and static routes are supporting configurations but do not activate the crypto map.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a static route to the remote peer's public IP address pointing to the next-hop router.
Why it's wrong here
A static route to the peer may be necessary for reachability, but it is not the configuration that activates the crypto map or determines which traffic is encrypted. The crypto map must be applied to an interface to process interesting traffic. The question asks for the additional configuration to apply the crypto map and establish the tunnel, not just routing.
- ✗
Enable NAT on the interface to translate the private subnet to a public address before encryption.
Why it's wrong here
NAT and IPsec can coexist, but NAT is not required to apply the crypto map or establish the tunnel. In fact, if NAT is applied to traffic that should be encrypted, it can break IPsec unless NAT-T or proper ordering is configured. The question focuses on applying the crypto map, not on address translation.
- ✗
Configure an ISAKMP policy with a matching pre-shared key on both peers.
Why it's wrong here
An ISAKMP policy and pre-shared key are required for IKE phase 1, but they do not apply the crypto map to an interface. The crypto map itself contains the peer, transform set, and ACL, and must be applied to an interface to become active. Without interface application, the tunnel will not initiate even if ISAKMP is correctly configured.
- ✓
Apply the crypto map to the outbound interface using the crypto map command under interface configuration.
Why this is correct
The crypto map must be applied to the interface that sends traffic to the remote peer, typically the WAN interface, using the crypto map <name> command. This enables the router to evaluate outbound packets against the ACL, match interesting traffic, and initiate the IPsec tunnel. Without applying the crypto map to an interface, the VPN configuration remains inactive.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.