CCNP Security Practice Question
A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?
⚠ Common exam trap
The trap here is either forgetting to enable PFS or selecting a weak Diffie-Hellman group, which would not satisfy the requirement for perfect forward secrecy with strong encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14
To achieve AES-256 encryption and perfect forward secrecy, the transform-set must specify esp-aes 256 and esp-sha256-hmac, and the crypto map must include set pfs with a strong Diffie-Hellman group such as group14. This ensures that each new IPsec SA uses a unique key derived from a fresh Diffie-Hellman exchange, providing forward secrecy. The combination of these commands meets the security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp without set pfs
Why it's wrong here
The transform-set correctly specifies AES-256 and SHA-256, but omitting the set pfs command means perfect forward secrecy is not enabled. Without PFS, the same keying material may be reused across rekeys, which does not meet the requirement. The engineer explicitly wants PFS, so this configuration is incomplete and incorrect.
- ✗
crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group5
Why it's wrong here
While the transform-set is correct for AES-256 and SHA-256, the set pfs group5 command enables PFS using Diffie-Hellman group 5 (1536-bit), which is not as strong as group14 and may not be supported on all platforms. However, the primary issue is that the question does not specify a group, but group14 is the modern recommendation. Group5 is deprecated in many environments, so this option is less correct than using group14.
- ✓
crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14
Why this is correct
The transform-set with esp-aes 256 and esp-sha256-hmac specifies AES-256 encryption and SHA-256 HMAC for integrity. The set pfs group14 command in the crypto map enables perfect forward secrecy using Diffie-Hellman group 14 (2048-bit). This combination meets both requirements: AES-256 encryption and PFS. The transform-set and crypto map together define the IPsec policy for the tunnel.
- ✗
crypto ipsec transform-set TS esp-3des esp-md5-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group2
Why it's wrong here
This option uses 3DES encryption, which is not AES-256, and MD5 HMAC, which is weaker than SHA-256. While it does enable PFS with group2, the encryption algorithm does not meet the AES-256 requirement. Therefore, this configuration fails to provide the desired level of encryption strength and is not correct for the scenario.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.