Drag a concept onto its matching description — or click a concept then click the description.
Phase 1 - establish IKE SA
Phase 2 - authenticate and establish first child SA
Drag and drop each IKEv2 exchange on the left to its matching phase on the right.
Drag a concept onto its matching description — or click a concept then click the description.
Phase 1 - establish IKE SA
Phase 2 - authenticate and establish first child SA
⚠ Common exam trap
IKEv2 simplifies the process to two phases, eliminating the separate Phase 1.5 and Phase 2 of IKEv1.
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
IKE_SA_INIT: Phase 1 - establish IKE SA
IKEv2 consists of only two phases: Phase 1 (IKE_SA_INIT) and Phase 2 (IKE_AUTH). CREATE_CHILD_SA, INFORMATIONAL, and rekey are exchanges that occur within the established IKE SA, not separate phases.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
IKE_SA_INIT: Phase 1 - establish IKE SA
Why this is correct
Correct: IKE_SA_INIT is Phase 1.
IKE_AUTH: Phase 2 - authenticate and establish first child SA
Why this is correct
Correct: IKE_AUTH is Phase 2.
Not a phase
Why this is correct
Incorrect: CREATE_CHILD_SA is not a separate phase; it is an exchange within the established IKE SA.
Not a phase
Why this is correct
Incorrect: INFORMATIONAL is used for error reporting and deletion, but not a separate phase.
Not a phase
Why this is correct
Incorrect: IKEv2 rekey is not a separate phase; it uses CREATE_CHILD_SA exchange.
Quick reference
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,175 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Drag and drop each IKEv2 exchange on the left to its matching phase on the right.
mediumWhy P1: IKE_SA_INIT is phase 1 for key agreement; IKE_AUTH is phase 2 for authentication and policy; CREATE_CHILD_SA is used for rekeying or additional SAs.
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.