mediumMultiple Choice
CCNP Practice Question: Runs the following command on Router R7: R7# show…
A network engineer runs the following command on Router R7:
R7# show crypto ikev2 sa detail
IKEv2 SAs:
Session-id:1, Status:UP-ACTIVE, IKE count:1, Child count:1
Tunnel-id Local Remote Status Role 1 10.1.1.1/4500 10.2.2.2/4500 READY INITIATOR Encr: AES-CBC 256, Hash: SHA256, DH Grp:14, Auth sign: PSK, Auth verify: PSK Life/Active Time: 86400/3600 sec
Child SA: Local selector 10.1.1.0/0 - 10.1.1.255/65535 Remote selector 10.2.2.0/0 - 10.2.2.255/65535 ESP spi in/out: 0x12345678/0x87654321
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the interpretation of 'show crypto ikev2 sa detail' output, and the trap here is that candidates may misinterpret 'READY' as a failure state or confuse 'Auth sign: PSK' with RSA signatures, especially when the output also shows encryption and hash algorithms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The tunnel is using pre-shared keys for authentication.
The output shows 'Auth sign: PSK' and 'Auth verify: PSK', which explicitly indicates that pre-shared keys (PSK) are used for IKEv2 authentication. The status 'READY' and 'UP-ACTIVE' confirm the SA is operational, not failed. Therefore, option B is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IKEv2 SA is in a failed state because it is READY.
Why it's wrong here
In Cisco IKEv2, the SA state of 'READY' is a normal, operational state that indicates the IKEv2 SA has been successfully established and is actively usable for securing traffic. It is not an error or failure state; rather, it reflects that both endpoints have completed the IKE_SA_INIT and IKE_AUTH exchanges and have installed the IPsec SAs. A failed SA would typically show a state such as 'DELETED', 'LARVAL', or be absent from the output entirely, not 'READY'.
- ✓
The tunnel is using pre-shared keys for authentication.
Why this is correct
The output directly shows 'Auth sign: PSK' and 'Auth verify: PSK', which are the IKEv2 authentication fields that specify the integrity/authentication algorithm used during the IKE_AUTH exchange. When both fields display 'PSK', the tunnel is unambiguously using pre-shared keys for authentication, meaning both peers derive the same symmetric key from a shared secret. This is a common, low-overhead authentication method in IPsec VPNs, and the Cisco CLI explicitly reports it in the 'show crypto ikev2 sa' or 'show crypto ikev2 profile' output.
- ✗
The tunnel is using RSA signatures for authentication.
Why it's wrong here
RSA signature authentication in IKEv2 would be indicated by 'Auth sign: RSA' (or 'RSA-SIG') and 'Auth verify: RSA' in the corresponding command output, as the router would use its RSA private key to sign the key exchange payload. In the given output, both fields show 'PSK', which is mutually exclusive with RSA signatures for the same Security Association because the authentication method is negotiated during IKEv2's initial exchange. Therefore, stating that the tunnel uses RSA signatures directly contradicts the observed authentication parameters and is incorrect.
- ✗
The IKEv2 SA has expired because the life time is 86400 seconds.
Why it's wrong here
The IKEv2 SA lifetime is the maximum duration (86400 seconds) or traffic volume it can exist before rekeying or expiration, but the SA only reaches that point after being active for that full time. The output also includes an active time of 3600 seconds, which is far below the lifetime threshold, meaning the SA is still well within its valid operational window. Furthermore, IKEv2 implementations proactively rekey before the hard lifetime expires, so an SA showing a remaining lifetime is not considered expired.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.