300-410 Infrastructure Security Practice Question
A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which crypto ACL configuration achieves this?
⚠ Common exam trap
The trap here is adding an explicit deny any any or using permit any any, misunderstanding that the implicit deny already handles non-matching traffic and that permit any any would encrypt everything.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
The correct crypto ACL is a single permit statement for the specific source and destination subnets. Because ACLs have an implicit deny at the end, all other traffic is not matched and therefore not encrypted. This precisely meets the requirement to encrypt only the specified traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 access-list 100 deny ip any any
Why it's wrong here
This ACL permits the desired traffic and then explicitly denies all other traffic. While this might seem correct, the explicit deny any any is redundant because there is an implicit deny at the end of every ACL. More importantly, the crypto ACL is used to match traffic for encryption; traffic that is denied is not encrypted, but it is also not necessarily dropped by the crypto ACL. The explicit deny does not change the encryption behavior but could cause confusion. The requirement is to encrypt only the specified traffic, and the permit statement alone achieves that because of the implicit deny.
- ✗
access-list 100 permit ip any any
Why it's wrong here
This ACL permits all IP traffic, which would cause all traffic between the sites to be encrypted, not just the specified subnets. This violates the requirement to encrypt only traffic between 10.1.1.0/24 and 10.2.2.0/24. It would also potentially attempt to encrypt traffic that should remain unencrypted, such as Internet-bound traffic.
- ✗
access-list 100 deny ip any any access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
Why it's wrong here
This ACL explicitly denies all IP traffic before permitting the desired subnet. In crypto ACLs, the first matching statement is used. The deny any any would match all traffic, causing no traffic to be encrypted, including the desired subnet. The permit statement would never be reached, so the VPN would not encrypt any traffic.
- ✓
access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
Why this is correct
This ACL permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24. In IPsec, the crypto ACL defines the traffic to be encrypted. By permitting only this specific traffic, all other traffic is implicitly denied and thus not encrypted, matching the requirement.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.