300-410 Infrastructure Security Practice Question
A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?
⚠ Common exam trap
Test-takers frequently confuse the ACL used for crypto map interesting traffic with an interface ACL, leading to applying the ACL to an interface instead of ensuring it is correctly referenced in the crypto map.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.
The crypto map uses an extended ACL to identify interesting traffic that should be encrypted. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, that traffic will not be encrypted. The engineer must ensure the ACL entries match the desired source and destination and that the crypto map references the correct ACL. This is a common misconfiguration when defining VPN traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the ACL to the outside interface with 'ip access-group VPN_TRAFFIC out'.
Why it's wrong here
Applying the ACL to an interface with 'ip access-group' filters traffic but does not define interesting traffic for IPsec. The crypto map uses the ACL to determine which packets to encrypt. Interface ACLs are separate and can cause conflicts. This action would not cause the traffic to be encrypted and might block it if not configured properly.
- ✓
Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.
Why this is correct
For IPsec to encrypt traffic, the ACL used in the crypto map must permit the interesting traffic. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, the router will not encrypt it. The engineer must verify that the ACL entries match the source and destination subnets and that the crypto map correctly references the ACL.
- ✗
Enable 'crypto ipsec transform-set' with the correct encapsulation mode.
Why it's wrong here
The transform set defines encryption and hashing algorithms, not which traffic is encrypted. If the transform set were misconfigured, the tunnel might fail to establish, but the symptom is that specific traffic is not encrypted. The issue is more likely with the ACL defining interesting traffic, not the transform set.
- ✗
Configure a route map to match the traffic and apply it to the crypto map.
Why it's wrong here
Route maps are used for policy-based routing or redistribution, not for defining IPsec interesting traffic. Crypto maps use extended ACLs to identify traffic to encrypt. A route map would not be referenced by the crypto map and thus would not solve the encryption issue.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.