Courseiva

350-401 · topic practice

Vpn Technologies practice questions

Practise ENCOR 350-401 Vpn Technologies practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Vpn Technologies

What the exam tests

What to know about Vpn Technologies

Vpn Technologies questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Vpn Technologies exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Vpn Technologies questions

20 questions · select your answer, then reveal the explanation

Question 1mediumdrag order
Read the full VPN explanation →

Drag and drop the steps of SSL VPN (AnyConnect) session establishment into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 2mediummatching
Read the full VPN explanation →

Drag and drop each SD-WAN policy type on the left to its matching application point on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Applied to data traffic for SLA-based path selection

Applied to enable NetFlow-like traffic monitoring

Applied to modify forwarding, NAT, or QoS on data packets

Applied to OMP routes and TLOCs for route manipulation

Applied to define which VPNs are provisioned on a device

Question 3mediummultiple choice
Read the full MPLS explanation →

An enterprise is migrating from a traditional MPLS WAN to Cisco SD-WAN. The network team has deployed vEdge routers at all branch offices and a vSmart controller in the data center. The engineer configures a centralized control policy to influence path selection based on cost and latency. After the policy is activated, the engineer notices that some branches are not receiving the updated policy and are still using the default best-path selection. The vSmart is reachable from all branches, and the vEdge routers show that they are connected to the vSmart. What is the most likely reason for this issue?

Question 4mediummatching
Read the full VPN explanation →

Drag and drop each DMVPN phase on the left to its matching NHRP operation type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hub-and-spoke with NHRP registration

Spoke-to-spoke dynamic tunnel via NHRP resolution request/reply

NHRP with prefix-based spoke-to-spoke shortcut

Question 5hardmultiple choice
Read the full VPN explanation →

An engineer is configuring a site-to-site VPN between two Cisco routers using IPsec with IKEv2. The engineer wants to use a pre-shared key. The configuration on both routers includes: crypto ikev2 proposal default, encryption aes-cbc-256, integrity sha256, group 14. The engineer also configures crypto ikev2 keyring and crypto ikev2 profile. The tunnel does not establish. The engineer sees that the IKEv2 SA is not created. What is the most likely missing configuration?

Question 6hardmulti select
Read the full VPN explanation →

Which three statements about DMVPN phase 2 are true? (Choose three.)

Question 7mediummatching
Open the full BGP breakdown →

Drag and drop each MP-BGP address family on the left to its matching use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Carries IPv4 VPN routes with MPLS labels across the provider core

Carries IPv6 VPN routes with MPLS labels across the provider core

Carries global IPv4 unicast routes (non-VPN)

Carries global IPv6 unicast routes (non-VPN)

Carries Layer 2 VPN information such as pseudowires and VPLS

Question 8mediumdrag order
Open the full BGP breakdown →

Drag and drop the steps of MP-BGP VPNv4 route advertisement between PE routers into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 9mediummatching
Read the full MPLS explanation →

Drag and drop each MPLS role on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Forwards MPLS packets by performing label lookup and swapping

Pushes labels on ingress and pops labels on egress

Core router that swaps labels without pushing or popping

Edge router that connects customer sites and runs MPLS VPNs

Customer edge router that connects to the PE

Question 10mediummulti select
Read the full MPLS explanation →

Which two statements about MPLS Layer 3 VPNs are true? (Choose two.)

Question 11mediumdrag order
Read the full VPN explanation →

Drag and drop the steps of DMVPN Phase 1 spoke-to-hub tunnel setup into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 12mediumdrag order
Read the full VPN explanation →

Drag and drop the steps of DMVPN Phase 3 spoke-to-spoke shortcut creation into the correct order, from first to last.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 13hardmulti select
Read the full MPLS explanation →

Which three statements about MPLS Layer 3 VPNs are true? (Choose three.)

Question 14mediummulti select
Read the full VPN explanation →

Which two statements about DMVPN Phase 2 are true? (Choose two.)

Question 15hardmulti select
Read the full VPN explanation →

Which two statements about DMVPN phase 2 are true? (Choose two.)

Question 16mediummulti select
Read the full VPN explanation →

Which two statements about IPsec IKEv2 are true? (Choose two.)

Question 17hardmulti select
Read the full VPN explanation →

Which three statements about SD-WAN overlay tunnels and transport are true? (Choose three.)

Question 18mediummatching
Read the full VPN explanation →

Drag and drop each SD-WAN plane on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

OMP route exchange and BGP/OSPF peering

IPsec tunnel encapsulation and packet forwarding

CLI, REST API, and web-based administration

vBond-based device authentication and onboarding

Telemetry collection and application visibility

Question 19hardmulti select
Read the full VPN explanation →

Which three statements about VRF-lite are true? (Choose three.)

Question 20mediummultiple choice
Open the full BGP breakdown →

An engineer is configuring MPLS L3VPN on a Cisco IOS-XR router. The VRF CUSTOMER_B is configured with route-target import 100:1 and export 100:1. The engineer notices that the VRF routes are not being advertised to the route reflector. The BGP session to the route reflector is established and the VPNv4 address family is activated. What is the missing configuration?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vpn Technologies sessions

Start a Vpn Technologies only practice session

Every question in these sessions is drawn from the Vpn Technologies domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Vpn Technologies?
Vpn Technologies questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vpn Technologies questions in a focused session?
Yes — the session launcher on this page draws every question from the Vpn Technologies domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.