300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?
⚠ Common exam trap
A common mix-up: candidates confuse IKEv1 and IKEv2 configuration syntax, or misplacing algorithm definitions under a policy or profile instead of a proposal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14
IKEv2 proposals define the encryption, integrity, and Diffie-Hellman group parameters. The correct command is crypto ikev2 proposal, followed by encryption aes-cbc-256, integrity sha256, and group 14. This proposal can then be referenced in an IKEv2 policy. The other options use incorrect commands or syntax for IKEv2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crypto ikev2 policy POLICY1 encryption aes-256 hash sha256 group 14
Why it's wrong here
The crypto ikev2 policy command is used to define an IKEv2 policy that references a proposal, not to directly configure encryption and integrity. The keywords encryption, hash, and group are not valid under crypto ikev2 policy. This command would result in an error. The correct place to define algorithms is under crypto ikev2 proposal.
- ✗
crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14
Why it's wrong here
This command is for IKEv1 (ISAKMP) policy, not IKEv2. The syntax uses 'encryption aes 256' and 'hash sha256', which are valid for IKEv1 but not for IKEv2. The scenario specifies IKEv2, so this is incorrect. IKEv2 uses a different configuration model with proposals and policies.
- ✓
crypto ikev2 proposal PROPOSAL1 encryption aes-cbc-256 integrity sha256 group 14
Why this is correct
This command sequence correctly defines an IKEv2 proposal with AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. IKEv2 proposals are configured under crypto ikev2 proposal, and the syntax matches the required parameters. This is the correct way to specify encryption and integrity algorithms for IKEv2.
- ✗
crypto ikev2 profile PROFILE1 encryption aes-cbc-256 integrity sha256 group 14
Why it's wrong here
The crypto ikev2 profile command is used to configure IKEv2 profile parameters such as authentication and identity, not encryption algorithms. Encryption and integrity are defined in a proposal. This command would not accept those keywords. The profile references a proposal but does not define the algorithms itself.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.