Courseiva
Infrastructure Security →easyMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?

⚠ Common exam trap

A common mix-up: candidates confuse IKEv1 and IKEv2 configuration syntax, or misplacing algorithm definitions under a policy or profile instead of a proposal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14

IKEv2 proposals define the encryption, integrity, and Diffie-Hellman group parameters. The correct command is crypto ikev2 proposal, followed by encryption aes-cbc-256, integrity sha256, and group 14. This proposal can then be referenced in an IKEv2 policy. The other options use incorrect commands or syntax for IKEv2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    crypto ikev2 policy POLICY1 encryption aes-256 hash sha256 group 14

    Why it's wrong here

    The crypto ikev2 policy command is used to define an IKEv2 policy that references a proposal, not to directly configure encryption and integrity. The keywords encryption, hash, and group are not valid under crypto ikev2 policy. This command would result in an error. The correct place to define algorithms is under crypto ikev2 proposal.

  • ✗

    crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14

    Why it's wrong here

    This command is for IKEv1 (ISAKMP) policy, not IKEv2. The syntax uses 'encryption aes 256' and 'hash sha256', which are valid for IKEv1 but not for IKEv2. The scenario specifies IKEv2, so this is incorrect. IKEv2 uses a different configuration model with proposals and policies.

  • ✓

    crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14

    Why this is correct

    This command sequence correctly defines an IKEv2 proposal with AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. IKEv2 proposals are configured under crypto ikev2 proposal, and the syntax matches the required parameters. This is the correct way to specify encryption and integrity algorithms for IKEv2.

  • ✗

    crypto ikev2 profile PROFILE1 encryption aes-cbc-256 integrity sha256 group 14

    Why it's wrong here

    The crypto ikev2 profile command is used to configure IKEv2 profile parameters such as authentication and identity, not encryption algorithms. Encryption and integrity are defined in a proposal. This command would not accept those keywords. The profile references a proposal but does not define the algorithms itself.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.