Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?

⚠ Common exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 proposal syntax, or placing proposal parameters under the policy command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14

The correct command to define an IKEv2 proposal with specific encryption, integrity, and DH group is under crypto ikev2 proposal, using the encryption, integrity, and group keywords. The policy command only references a proposal, and ISAKMP policy is for IKEv1. The keyring is for authentication, not proposal parameters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14

    Why this is correct

    This command sequence under crypto ikev2 proposal correctly specifies AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. In Cisco IOS, the IKEv2 proposal is configured with the encryption, integrity, and group keywords, and this syntax matches the required parameters for the proposal.

  • ✗

    crypto ikev2 keyring KEYRING peer SITE address 1.1.1.1 pre-shared-key local secret

    Why it's wrong here

    This command configures an IKEv2 keyring for pre-shared key authentication, not the proposal parameters. The keyring defines peer identities and keys, but it does not set encryption, integrity, or Diffie-Hellman group. Therefore, it does not satisfy the requirement to define the IKEv2 proposal with AES-256, SHA-256, and group 14.

  • ✗

    crypto isakmp policy 10 encryption aes 256 hash sha256 group 14

    Why it's wrong here

    This command configures an IKEv1 ISAKMP policy, not an IKEv2 proposal. The requirement specifies IKEv2, so using crypto isakmp policy would not meet the design. Additionally, the syntax for encryption in IKEv1 is 'encryption aes 256', which differs from IKEv2's 'encryption aes-cbc-256'.

  • ✗

    crypto ikev2 policy POLICY proposal PROP encryption aes-256 integrity sha256 group 14

    Why it's wrong here

    The crypto ikev2 policy command is used to associate a proposal with a policy, but the encryption, integrity, and group parameters belong in the proposal configuration, not in the policy command line. This syntax is invalid because the policy command does not accept those parameters directly; they must be configured under the proposal.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.