Courseiva
mediumMultiple Choice

CCNP Practice Question: Examine this configuration for a site-to-site VPN…

Examine this configuration for a site-to-site VPN on a Cisco router:

crypto isakmp policy 10

encryption aes 256 hash sha256 authentication pre-share group 14 lifetime 86400 !

crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac

mode tunnel !

crypto map CMAP 10 ipsec-isakmp

set peer 192.168.1.1 set transform-set TSET match address 101 !

interface GigabitEthernet0/0/0
 ip address 10.0.0.1 255.255.255.0
 crypto map CMAP

!

access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255

Which statement about this configuration is true?

⚠ Common exam trap

Cisco often tests the misconception that the crypto map should be applied to a tunnel interface, but in reality it must be applied to the physical egress interface for site-to-site VPNs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The access-list 101 defines the traffic that will be encrypted; traffic from 192.168.10.0/24 to 192.168.20.0/24 will be protected.

Access-list 101 is used by the crypto map to match traffic that should be encrypted via IPsec. The ACL permits traffic from source network 192.168.10.0/24 to destination network 192.168.20.0/24, so that traffic will be protected by the IPsec tunnel. This is the standard method for defining interesting traffic in a site-to-site VPN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The crypto map uses IKEv2 for key exchange because the transform set uses SHA-256.

    Why it's wrong here

    The transform set's use of SHA-256 does not indicate IKEv2. IKE version is determined by the configuration commands: 'crypto isakmp' invokes IKEv1, whereas 'crypto ikev2' is required for IKEv2. SHA-256 is an authentication hash that can be used in both IKEv1 and IKEv2 transform sets, so it has no bearing on the IKE version. This option is incorrect because the presence of 'crypto isakmp' in the configuration confirms IKEv1, not IKEv2.

  • ✓

    The access-list 101 defines the traffic that will be encrypted; traffic from 192.168.10.0/24 to 192.168.20.0/24 will be protected.

    Why this is correct

    Access-list 101 is referenced by the crypto map's 'match address 101' statement, which defines the interesting traffic that will be protected by IPsec. The ACL explicitly permits traffic from source network 192.168.10.0/24 to destination network 192.168.20.0/24, so only that traffic triggers the establishment of the IPsec security association. This is correct because without a matching ACL entry, no traffic would be encrypted and the VPN would not carry any payload.

  • ✗

    The ISAKMP policy lifetime of 86400 seconds is too long and will cause the tunnel to fail.

    Why it's wrong here

    An ISAKMP policy lifetime of 86400 seconds is exactly the default lifetime for IKEv1 phase 1 SA, which is one day. This is a standard and acceptable value that does not cause the tunnel to fail. In fact, many production configurations use this default or even longer lifetimes to reduce the overhead of renegotiation. The tunnel failure would only occur if the lifetime were misconfigured in a way that causes a mismatch between peers, but 86400 is a common default.

  • ✗

    The crypto map should be applied to the tunnel interface, not the physical interface.

    Why it's wrong here

    For a traditional site-to-site IPsec VPN using crypto maps, the crypto map must be applied to the physical interface (or a subinterface) that carries the encrypted traffic, not to a tunnel interface. Tunnel interfaces are used for other VPN technologies such as VTI (Virtual Tunnel Interface) or DMVPN, where the tunnel itself is the IPsec endpoint. Applying a crypto map to a tunnel interface is invalid because crypto maps are designed to be bound to the outside physical interface that faces the remote peer.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.