Courseiva
Infrastructure Security →hardMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?

⚠ Common exam trap

Test-takers frequently confuse the ACL used for crypto map interesting traffic with an interface ACL, leading to applying the ACL to an interface instead of ensuring it is correctly referenced in the crypto map.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.

The crypto map uses an extended ACL to identify interesting traffic that should be encrypted. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, that traffic will not be encrypted. The engineer must ensure the ACL entries match the desired source and destination and that the crypto map references the correct ACL. This is a common misconfiguration when defining VPN traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the ACL to the outside interface with 'ip access-group VPN_TRAFFIC out'.

    Why it's wrong here

    Applying the ACL to an interface with 'ip access-group' filters traffic but does not define interesting traffic for IPsec. The crypto map uses the ACL to determine which packets to encrypt. Interface ACLs are separate and can cause conflicts. This action would not cause the traffic to be encrypted and might block it if not configured properly.

  • ✓

    Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.

    Why this is correct

    For IPsec to encrypt traffic, the ACL used in the crypto map must permit the interesting traffic. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, the router will not encrypt it. The engineer must verify that the ACL entries match the source and destination subnets and that the crypto map correctly references the ACL.

  • ✗

    Enable 'crypto ipsec transform-set' with the correct encapsulation mode.

    Why it's wrong here

    The transform set defines encryption and hashing algorithms, not which traffic is encrypted. If the transform set were misconfigured, the tunnel might fail to establish, but the symptom is that specific traffic is not encrypted. The issue is more likely with the ACL defining interesting traffic, not the transform set.

  • ✗

    Configure a route map to match the traffic and apply it to the crypto map.

    Why it's wrong here

    Route maps are used for policy-based routing or redistribution, not for defining IPsec interesting traffic. Crypto maps use extended ACLs to identify traffic to encrypt. A route map would not be referenced by the crypto map and thus would not solve the encryption issue.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.