300-410 VPN Technologies Practice Question
A network architect is designing a FlexVPN solution using IKEv2 between a hub and multiple spokes. The hub must authenticate spokes using certificates, and spokes must authenticate the hub. The architect wants to ensure that the hub can verify the revocation status of spoke certificates in real time. Which mechanism should be implemented?
⚠ Common exam trap
The trap here is equating CRL with real-time revocation; CRLs are downloaded periodically and can be stale, whereas OCSP queries the responder immediately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure OCSP on the hub.
OCSP provides real-time certificate revocation status by allowing the hub to query an OCSP responder during IKEv2 authentication. CRL checking is periodic and may not reflect recent revocations. SCEP is for enrollment, and pre-shared keys are a different authentication method. Therefore, OCSP is the correct choice for real-time revocation checking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure CRL checking on the hub.
Why it's wrong here
CRL checking involves downloading a certificate revocation list periodically, which is not real-time. While CRLs can be used, they may be stale between downloads. The requirement for real-time revocation status points to a more immediate method like OCSP.
- ✓
Configure OCSP on the hub.
Why this is correct
OCSP (Online Certificate Status Protocol) allows the hub to query an OCSP responder in real time to check the revocation status of a spoke's certificate during IKEv2 authentication. This meets the real-time requirement. Cisco IOS supports OCSP for IKEv2, enabling immediate revocation checks.
- ✗
Enable certificate enrollment using SCEP.
Why it's wrong here
SCEP (Simple Certificate Enrollment Protocol) is used for certificate enrollment, not revocation checking. It allows devices to request and obtain certificates from a CA, but does not provide real-time revocation status. Therefore, it does not satisfy the requirement.
- ✗
Use pre-shared keys with certificate mapping.
Why it's wrong here
Pre-shared keys are an alternative authentication method, not a revocation checking mechanism. Combining them with certificate mapping does not provide real-time revocation status. The scenario specifically requires certificate-based authentication and real-time revocation, so this is not appropriate.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.