Courseiva
mediumMultiple Choice

CCNP Practice Question: Examine the following IPsec configuration…

Examine the following IPsec configuration snippet:

crypto ikev2 proposal IKEV2_PROP

encryption aes-cbc-256 integrity sha256 group 14 !

crypto ikev2 policy IKEV2_POL

proposal IKEV2_PROP !

crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac

mode tunnel !

crypto ipsec profile IPSEC_PROF

set transform-set TSET set ikev2-profile IKEV2_POL

Which statement about this configuration is true?

⚠ Common exam trap

Cisco often tests the distinction between the IKEv2 proposal (control plane) and the IPsec transform set (data plane), and the trap here is that candidates might confuse the 'set ikev2-profile' command syntax or assume PFS is mandatory, when in fact the configuration is valid as shown.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The transform set uses ESP with AES-256 encryption and SHA-256 HMAC for authentication.

The transform set explicitly uses 'esp-aes 256' for encryption and 'esp-sha256-hmac' for authentication, which matches the description of ESP with AES-256 encryption and SHA-256 HMAC. The IKEv2 proposal and profile are correctly configured, and the 'mode tunnel' command ensures the transform set operates in tunnel mode, which is appropriate for site-to-site VPNs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The transform set uses ESP with AES-256 encryption and SHA-256 HMAC for authentication.

    Why this is correct

    The transform set is correctly defined. The commands `esp-aes 256` and `esp-sha256-hmac` under `crypto ipsec transform-set` specify the Encapsulating Security Payload (ESP) with AES-256 for confidentiality and the SHA-256 HMAC variant for integrity and authentication. This is a valid and secure combination for a site-to-site IPsec VPN. The statement matches the configuration, making it the correct answer.

  • ✗

    The IKEv2 proposal uses AES-256, SHA-256, and DH group 14, but the IPsec profile will not apply because the ikev2-profile command is missing the 'set' keyword.

    Why it's wrong here

    The `set` keyword is indeed present. In Cisco IOS, the IPsec profile references the IKEv2 parameter set using the command `set ikev2-profile IKEV2_POL`; omitting `set` would make the command invalid, but here it is explicitly listed. Additionally, there is no requirement that the IKEv2 policy name differ from the profile name—they can be identical. Therefore the IPsec profile will apply as intended.

  • ✗

    The transform set is configured in transport mode, which is incorrect for site-to-site VPN.

    Why it's wrong here

    This claim is false because the transform set is not in transport mode. The configuration explicitly includes the `mode tunnel` command, which overrides the default transport mode and sets the transform set to use IPsec tunnel mode—essential for site-to-site VPNs that encapsulate the entire original IP packet. Transport mode is typically used only for end-to-end host communications or within a GRE-protected tunnel, not for classic site-to-site IPsec deployments. Thus, this option is wrong.

  • ✗

    The IPsec profile is incomplete because it does not include a PFS (Perfect Forward Secrecy) setting.

    Why it's wrong here

    PFS (Perfect Forward Secrecy) is not a required element of a valid IPsec profile. In Cisco IOS, PFS is enabled via the `set pfs` command within the crypto map or IPsec profile; while it improves security by ensuring session keys are not derived from persistent keys, its absence does not make the configuration incomplete. The profile can still be applied and the VPN will function correctly. Therefore, claiming the profile is incomplete for lacking PFS is incorrect.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.