300-410 VPN Technologies Practice Question
A network administrator is deploying FlexVPN between a Cisco IOS headend and several remote spokes. The design requires that each spoke be assigned a unique virtual IP address from a pool on the headend, and that the headend pushes a specific DNS server address to each spoke during IKEv2 negotiation. Which configuration element on the headend provides the DNS server address to the spokes?
⚠ Common exam trap
A common mix-up: candidates confuse the address-assignment pool with the attribute-delivery policy, so the engineer picks the pool for a value it does not carry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An IKEv2 authorization policy that specifies the DNS server and is referenced by the IKEv2 profile.
FlexVPN uses IKEv2 configuration attributes to deliver parameters such as virtual IP addresses, DNS servers, and split-tunnel information to spokes. The headend's IKEv2 authorization policy defines these attributes, and the IKEv2 profile references the authorization policy so the values are returned during IKE_AUTH. The local IP pool supplies addresses, but the DNS server specifically comes from the authorization policy, making it the correct element for the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A crypto pki trustpoint that includes the DNS server in the certificate subject alternative name field.
Why it's wrong here
A PKI trustpoint and certificate subject alternative names are used for identity and certificate validation, not for dynamic configuration delivery. Embedding a DNS server in a certificate does not push that value into the spoke's IKEv2 configuration. The spoke would still need an authorization policy or equivalent attribute delivery to learn the DNS server, so this does not meet the requirement.
- ✓
An IKEv2 authorization policy that specifies the DNS server and is referenced by the IKEv2 profile.
Why this is correct
In FlexVPN, the IKEv2 authorization policy carries attributes such as the DNS server, the virtual IP pool, and the split-tunnel ACL that the headend pushes to the spoke. When the IKEv2 profile references the authorization policy, the headend can return the DNS server address in the IKE_AUTH exchange. This is the correct mechanism for delivering the requested DNS attribute to each spoke.
- ✗
A local IP pool configured with the ip local pool command and referenced under the virtual-template interface.
Why it's wrong here
A local IP pool supplies virtual IP addresses to spokes, not DNS server information. While the pool is required for address assignment, it cannot carry the DNS attribute. The DNS server must be delivered through the authorization policy, so referencing the pool alone leaves the spoke without the requested DNS configuration. This option addresses only the addressing half of the requirement.
- ✗
A dynamic routing protocol such as OSPF configured on the virtual-template interface to advertise the DNS server.
Why it's wrong here
Routing protocols advertise reachability information, not host configuration parameters like DNS server addresses. OSPF or EIGRP on the virtual-template can make the DNS server reachable, but it will not tell the spoke which DNS server to use. The requirement is to push a configuration attribute during IKEv2, which is done by the authorization policy, not by a routing protocol.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.