Courseiva
VPN Technologies →hardMultiple Choice

300-410 VPN Technologies Practice Question

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?

⚠ Common exam trap

The trap here is assuming that 'show crypto ipsec sa' alone can confirm ACL matches, but it only shows encrypted packets, not the ACL hit counters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

show access-lists

When an IPsec tunnel is up but traffic is not passing, a common cause is a mismatch between the crypto ACL and the actual traffic. The crypto ACL defines interesting traffic that should be encrypted. By using 'show access-lists', you can see if the ACL's permit entries are being hit by the traffic. If counters are not incrementing, the traffic is not matching the ACL, and you need to adjust it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    show access-lists

    Why this is correct

    'show access-lists' displays the configured ACLs and their hit counters. By examining the crypto ACL referenced in the crypto map, you can see if the counters are incrementing for the interesting traffic. If the counters are not incrementing, the ACL may not match the traffic, indicating a mismatch. This is a key step in troubleshooting IPsec VPNs when the tunnel is up but traffic is not flowing.

  • ✗

    show crypto ipsec sa

    Why it's wrong here

    'show crypto ipsec sa' displays the IPsec security associations, including the local and remote networks, encryption and authentication algorithms, and packet counters. While it can show if packets are being encrypted and decrypted, it does not directly show the crypto ACL configuration or whether it matches the traffic. It is useful for verifying that the SA is established and passing traffic, but not for checking ACL matches.

  • ✗

    show crypto isakmp sa

    Why it's wrong here

    'show crypto isakmp sa' displays the IKE security associations, including the peer, state, and authentication method. It is used to verify that Phase 1 (IKE) is established. However, it does not provide information about the crypto ACL or whether traffic is matching it. If the tunnel is up, IKE SA is likely fine, so this command is not the best for troubleshooting traffic selection issues.

  • ✗

    show crypto map

    Why it's wrong here

    'show crypto map' displays the crypto map configuration, including the peer, the ACL used, and the transform set. It shows which ACL is referenced, but it does not show whether that ACL matches the actual traffic being sent. To verify matching, you need to see the ACL itself and the traffic counters, which is done with 'show access-lists' or 'show crypto ipsec sa' for encrypted packets.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.