300-410 VPN Technologies Practice Question
A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The customer requires that traffic for the 10.1.1.0/24 subnet be encrypted, but all other traffic must be sent unencrypted. The engineer applies a crypto map to the outside interface. Which additional configuration is required to meet this requirement?
⚠ Common exam trap
It's easy for candidates to confuse standard ACLs with extended ACLs for crypto map match address, or reversing the permit/deny logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an extended ACL that permits IP traffic from 10.1.1.0/24 to the remote subnet and apply it to the crypto map as the match address.
The match address in a crypto map must reference an extended ACL that permits the traffic to be encrypted. Only traffic permitted by this ACL will be protected; all other traffic is sent unencrypted. Therefore, an extended ACL permitting the desired subnet is required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an extended ACL that permits IP traffic from 10.1.1.0/24 to the remote subnet and apply it to the crypto map as the match address.
Why this is correct
The match address in a crypto map references an extended ACL that defines the traffic to be encrypted. Permitting only traffic from the local 10.1.1.0/24 to the remote subnet ensures that only that traffic is protected, while other traffic is sent unencrypted because it does not match the ACL.
- ✗
Configure a standard ACL that permits the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
Why it's wrong here
Standard ACLs cannot be used as the match address for a crypto map because they cannot specify destination addresses or protocols. The crypto map requires an extended ACL to identify traffic flows by source and destination, so a standard ACL would not correctly define the interesting traffic.
- ✗
Configure a route map that matches the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
Why it's wrong here
Crypto maps do not use route maps to define interesting traffic. The match address command specifically requires an extended ACL. A route map is used for other purposes such as route redistribution or policy-based routing, not for selecting VPN traffic.
- ✗
Configure an extended ACL that denies IP traffic from 10.1.1.0/24 to the remote subnet and apply it as the match address.
Why it's wrong here
The ACL used in a crypto map match address must permit the traffic that needs encryption. If the ACL denies the traffic, that traffic will not be encrypted and will be sent in clear text. The deny statement would exclude the desired traffic from the VPN.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.