Courseiva
VPN Technologies →hardMultiple Choice

300-410 VPN Technologies Practice Question

A network administrator is deploying FlexVPN between a Cisco IOS headend and several remote spokes. The design requires that each spoke be assigned a unique virtual IP address from a pool on the headend, and that the headend pushes a specific DNS server address to each spoke during IKEv2 negotiation. Which configuration element on the headend provides the DNS server address to the spokes?

⚠ Common exam trap

A common mix-up: candidates confuse the address-assignment pool with the attribute-delivery policy, so the engineer picks the pool for a value it does not carry.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An IKEv2 authorization policy that specifies the DNS server and is referenced by the IKEv2 profile.

FlexVPN uses IKEv2 configuration attributes to deliver parameters such as virtual IP addresses, DNS servers, and split-tunnel information to spokes. The headend's IKEv2 authorization policy defines these attributes, and the IKEv2 profile references the authorization policy so the values are returned during IKE_AUTH. The local IP pool supplies addresses, but the DNS server specifically comes from the authorization policy, making it the correct element for the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A crypto pki trustpoint that includes the DNS server in the certificate subject alternative name field.

    Why it's wrong here

    A PKI trustpoint and certificate subject alternative names are used for identity and certificate validation, not for dynamic configuration delivery. Embedding a DNS server in a certificate does not push that value into the spoke's IKEv2 configuration. The spoke would still need an authorization policy or equivalent attribute delivery to learn the DNS server, so this does not meet the requirement.

  • ✓

    An IKEv2 authorization policy that specifies the DNS server and is referenced by the IKEv2 profile.

    Why this is correct

    In FlexVPN, the IKEv2 authorization policy carries attributes such as the DNS server, the virtual IP pool, and the split-tunnel ACL that the headend pushes to the spoke. When the IKEv2 profile references the authorization policy, the headend can return the DNS server address in the IKE_AUTH exchange. This is the correct mechanism for delivering the requested DNS attribute to each spoke.

  • ✗

    A local IP pool configured with the ip local pool command and referenced under the virtual-template interface.

    Why it's wrong here

    A local IP pool supplies virtual IP addresses to spokes, not DNS server information. While the pool is required for address assignment, it cannot carry the DNS attribute. The DNS server must be delivered through the authorization policy, so referencing the pool alone leaves the spoke without the requested DNS configuration. This option addresses only the addressing half of the requirement.

  • ✗

    A dynamic routing protocol such as OSPF configured on the virtual-template interface to advertise the DNS server.

    Why it's wrong here

    Routing protocols advertise reachability information, not host configuration parameters like DNS server addresses. OSPF or EIGRP on the virtual-template can make the DNS server reachable, but it will not tell the spoke which DNS server to use. The requirement is to push a configuration attribute during IKEv2, which is done by the authorization policy, not by a routing protocol.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.