mediumMultiple Select
CCNP Practice Question: Which two statements about IPsec IKEv2 are true?…
Which two statements about IPsec IKEv2 are true? (Choose two.)
⚠ Common exam trap
The trap here is assuming IKEv2 is backward compatible with IKEv1 or that it only supports PSK — candidates who confuse IKEv1 limitations with IKEv2 features pick the wrong options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP port 4500 for NAT traversal.
Option A is correct because IKEv2 performs its initial IKE_SA_INIT exchange over UDP port 500, and when NAT is detected it switches to UDP port 4500 (NAT-T) to encapsulate ESP/IKE traffic and traverse NAT devices. Option C is correct because IKEv2 natively supports EAP methods (e.g., EAP-MSCHAPv2, EAP-TLS) as an authentication mechanism, which is commonly used for remote-access VPN clients. Option B is wrong because IKEv2 establishes the IKE SA once and then creates multiple child SAs (IPsec SAs) under that single IKE SA without requiring a separate authentication phase for each. Option D is wrong because IKEv2 supports multiple authentication methods including pre-shared keys, digital certificates (RSA/ECDSA), and EAP. Option E is wrong because IKEv2 is not backward compatible with IKEv1; the two versions do not interoperate and require separate implementations or negotiation fallback mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP port 4500 for NAT traversal.
Why this is correct
IKEv2 begins negotiation over UDP 500, then detects NAT along the path and switches to UDP 4500, which encapsulates ESP-in-UDP to survive address translation. This satisfies the stem's NAT traversal requirement, since port 4500 allows the encrypted payload to pass through NAT devices that would otherwise drop native ESP packets.
- ✗
IKEv2 requires a separate authentication phase for each security association established.
Why it's wrong here
IKEv2 establishes the IKE SA once, then creates multiple child SAs without re-authenticating each time. It is tempting because IKEv1 aggressive and quick modes involve extra exchanges, and it would be correct if describing IKEv1's phase structure rather than IKEv2's.
- ✓
IKEv2 supports EAP authentication for remote access VPNs.
Why this is correct
IKEv2 natively carries EAP payloads within its authentication exchange, letting remote access VPN clients authenticate via EAP methods such as MSCHAPv2 or certificate-based EAP-TLS. This satisfies the remote access VPN requirement, unlike IKEv1, where EAP support was bolted on through Cisco-proprietary extensions.
- ✗
IKEv2 uses only pre-shared keys for authentication and does not support digital certificates.
Why it's wrong here
IKEv2 supports digital certificates, RSA signatures and EAP authentication, so restricting it to pre-shared keys is false. It is tempting because PSK remains a valid IKEv2 method, and it would be true for simple site-to-site tunnels where certificates are deliberately avoided.
- ✗
IKEv2 is backward compatible with IKEv1 and can interoperate with older peers.
Why it's wrong here
IKEv2 does not interoperate with IKEv1 peers; the two versions negotiate independently and cannot form a tunnel together. It is tempting because IKEv2 is the successor to IKEv1, and it would be correct if the statement described IKEv1's own backward compatibility with earlier implementations.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two statements about IPsec IKEv2 are true? (Choose two.)
medium- ✓ A.IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP 4500 for NAT traversal.
- ✓ B.IKEv2 supports EAP authentication for remote access VPNs.
- C.IKEv2 uses TCP port 500 for control plane messages.
- D.IKEv2 requires a separate IPsec SA for each direction of traffic.
- E.IKEv2 is not compatible with certificate-based authentication.
Why A: Option A is correct because IKEv2 performs its initial IKE_SA_INIT exchange over UDP port 500, and when a NAT device is detected it switches to UDP port 4500 using NAT-T encapsulation to keep the ESP/IKE traffic traversable. Option B is correct because IKEv2 natively supports EAP methods (for example EAP-MSCHAPv2 or EAP-TLS), which is why it is widely used for remote-access VPN client authentication. Option C is wrong because IKEv2 never uses TCP port 500; IKE runs over UDP. Option D is wrong because IKEv2 negotiates IPsec SAs as bidirectional pairs, so a single SA covers both directions rather than requiring one SA per direction. Option E is wrong because IKEv2 fully supports certificate-based authentication via the CERT and AUTH payloads.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.