300-410 VPN Technologies Practice Question
A network engineer is implementing FlexVPN with IKEv2 between a hub and multiple spokes. The hub uses a single IKEv2 profile and a single IPsec profile. The engineer wants to ensure that each spoke can authenticate using a unique pre-shared key. Which IKEv2 keyring configuration should be used on the hub?
⚠ Common exam trap
The trap here is thinking that multiple IKEv2 profiles or keyrings are required to support unique pre-shared keys per spoke, when a single keyring with multiple peer entries suffices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A single keyring with multiple peer entries, each specifying a different pre-shared key and matching the spoke's IP address.
FlexVPN supports a single IKEv2 keyring with multiple peer entries. Each peer entry can specify a unique pre-shared key and match criteria based on the spoke's identity, such as IP address or FQDN. The hub's IKEv2 profile references this keyring, and during IKEv2 authentication, the hub selects the appropriate key based on the peer's identity. This allows unique keys per spoke without needing multiple profiles or keyrings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A single keyring with multiple peer entries, each specifying the same pre-shared key but different identities.
Why it's wrong here
Using the same pre-shared key for all spokes does not provide unique keys. The identities can differ, but the key is shared, which violates the requirement. This approach is less secure and does not meet the design goal. Therefore, it is not correct.
- ✗
Multiple keyrings, each with a single peer entry, and multiple IKEv2 profiles referencing each keyring.
Why it's wrong here
While this would work, it is not the most efficient or scalable solution. FlexVPN is designed to use a single IKEv2 profile and keyring with multiple peer entries. Creating multiple profiles and keyrings increases configuration complexity and is unnecessary. The hub can match different spokes within a single keyring using peer entries. Thus, this is not the recommended configuration.
- ✓
A single keyring with multiple peer entries, each specifying a different pre-shared key and matching the spoke's IP address.
Why this is correct
In FlexVPN, the IKEv2 keyring can contain multiple peer entries, each with a different pre-shared key and a match statement for the spoke's identity (e.g., IP address). This allows the hub to use a unique key for each spoke while maintaining a single keyring. The IKEv2 profile references this keyring, and the hub selects the appropriate key based on the peer's identity. This is the correct and scalable approach.
- ✗
A single keyring with a single peer entry using a wildcard pre-shared key that matches all spokes.
Why it's wrong here
A wildcard pre-shared key would mean all spokes use the same key, which does not meet the requirement of unique keys per spoke. While it simplifies configuration, it reduces security because compromise of one key affects all spokes. The requirement explicitly states unique pre-shared keys, so this is incorrect.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.