Courseiva

350-401 · topic practice

Vpn Technologies practice questions

Practise ENCOR 350-401 Vpn Technologies practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Vpn Technologies

What the exam tests

What to know about Vpn Technologies

Vpn Technologies questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Vpn Technologies exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Vpn Technologies questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full MPLS explanation →

A network engineer is configuring MPLS L3VPN on a Cisco IOS-XE router. The VRF CUSTOMER_C has route-target import 300:1 and export 300:1. The PE receives VPNv4 routes from the route reflector, but the CE router connected to the PE cannot ping any remote site IP addresses. The PE can ping the remote site IP addresses from the VRF. What is the most likely cause?

Question 2mediummultiple choice
Read the full VPN explanation →

Examine the following IPsec configuration snippet:

crypto ikev2 proposal IKEV2_PROP

encryption aes-cbc-256 integrity sha256 group 14 !

crypto ikev2 policy IKEV2_POL

proposal IKEV2_PROP !

crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac

mode tunnel !

crypto ipsec profile IPSEC_PROF

set transform-set TSET set ikev2-profile IKEV2_POL

Which statement about this configuration is true?

Question 3mediummultiple choice
Read the full VPN explanation →

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not advertising EVPN routes for a specific VNI. The NVE interface is up, and the VNI is configured. Which action should the engineer take to verify that the VNI is properly associated with the EVPN control plane?

Question 4mediummatching
Read the full VPN explanation →

Drag and drop each DMVPN phase on the left to its matching NHRP operation type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hub-and-spoke with NHRP registration

Spoke-to-spoke dynamic tunnel via NHRP resolution request/reply

NHRP with prefix-based spoke-to-spoke shortcut

Question 5mediummultiple choice
Read the full VPN explanation →

A network team is designing an SD-WAN overlay for a multinational enterprise with 500+ branch sites. The design must ensure that control plane traffic (e.g., OMP updates) is encrypted and authenticated between all vSmart controllers and vEdge routers, while allowing data plane traffic to use IPsec tunnels between branch sites directly. Which architectural element is responsible for orchestrating the initial authentication and certificate enrollment of all SD-WAN devices?

Question 6hardmulti select
Read the full VPN explanation →

A network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)

Question 7mediummultiple choice
Review the full OSPF breakdown →

An engineer is troubleshooting an MPLS VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are running OSPF with the CE routers. On PE1, the 'show ip route vrf CUSTOMER' output shows 10.2.2.0/24 as an OSPF route, but the prefix is not present in the global BGP table. What is the most likely cause?

Question 8mediummulti select
Read the full VPN explanation →

Which three statements about VRF path isolation in a service provider network are true? (Choose three.)

Question 9hardmultiple choice
Read the full wireless explanation →

An enterprise network uses TACACS+ for device administration and RADIUS for network access (VPN and wireless). The TACACS+ server is configured to authorize commands. A network engineer notices that after a recent upgrade of the TACACS+ server software, some commands that were previously authorized are now being denied. The engineer checks the router configuration and sees 'aaa authorization commands 15 default group tacacs+'. The TACACS+ server logs show that the authorization requests are being sent and responded to. What is the most likely cause?

Question 10mediumdrag order
Read the full VPN explanation →

Drag and drop the steps of DMVPN Phase 1 spoke-to-hub tunnel setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 11easymultiple choice
Read the full VPN explanation →

Which IPsec protocol provides both encryption and authentication within a single ESP header?

Question 12hardmultiple choice
Read the full VPN explanation →

An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?

Exhibit

Refer to the exhibit.

! NVE configuration
interface nve1
 no shut
 source-interface Loopback0
 member vni 10100
  mcast-group 239.1.1.100
!
! VRF configuration
vrf context TENANT-A
 rd 65000:1
 address-family ipv4 unicast
  route-target both 65000:100
 exit-address-family
!
! BGP EVPN configuration
router bgp 65000
 neighbor 10.1.1.1 remote-as 65000
 neighbor 10.1.1.1 update-source Loopback0
 address-family l2vpn evpn
  neighbor 10.1.1.1 activate
  neighbor 10.1.1.1 send-community extended
!
! VLAN configuration
vlan 100
 vn-segment 10100
!
! Interface configuration
interface Vlan100
 no shutdown
 vrf member TENANT-A
 ip address 192.168.100.1/24
Question 13mediumdrag order
Read the full VPN explanation →

Drag and drop the steps of DMVPN Phase 2 NHRP resolution process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 14mediummultiple choice
Read the full VPN explanation →

A network engineer is designing a new data center leaf-spine fabric using Cisco Nexus 9000 switches. The design requires that the fabric automatically discover the IP addresses of remote VTEPs participating in a VXLAN EVPN deployment. Which control-plane protocol should be enabled on the leaf switches to provide this dynamic VTEP discovery?

Question 15mediummulti select
Read the full VPN explanation →

A network architect is designing a data center fabric that uses VXLAN with an EVPN control plane on Cisco Nexus 9000 switches. The architect must justify why EVPN is preferred over a flood-and-learn VXLAN data plane. Which two statements correctly describe advantages of using an EVPN control plane in this design? (Choose two.)

Question 16hardmultiple choice
Read the full VPN explanation →

A network engineer is implementing VXLAN with an Ethernet VPN (EVPN) control plane in a data center. The underlay is a Layer 3 IP network. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and that the fabric supports multihoming with all-active forwarding. Which technology should be used?

Question 17hardmulti select
Read the full VPN explanation →

A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)

Question 18hardmultiple choice
Read the full VPN explanation →

A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN using IPsec. The engineer wants to ensure that the VPN tunnel only carries traffic for the subnet 10.1.1.0/24 to 10.2.2.0/24. Which configuration element is required to define the interesting traffic?

Question 19hardmulti select
Read the full VPN explanation →

A network engineer is implementing VXLAN with an EVPN control plane in a data center. The engineer must ensure that the underlay network supports the required traffic and that the overlay provides optimal forwarding. Which two statements are true regarding this implementation? (Choose two.)

Question 20mediummulti select
Read the full VPN explanation →

A network engineer is configuring a Cisco IOS XE router to support a site-to-site VXLAN tunnel over an existing IP underlay. The engineer must configure the NVE interface and ensure that the underlay provides the necessary transport. Which two statements are true about this configuration? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vpn Technologies sessions

Start a Vpn Technologies only practice session

Every question in these sessions is drawn from the Vpn Technologies domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Vpn Technologies?
Vpn Technologies questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vpn Technologies questions in a focused session?
Yes — the session launcher on this page draws every question from the Vpn Technologies domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.