Courseiva
VPN Technologies →hardMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is implementing FlexVPN with IKEv2 between a hub and multiple spokes. The hub uses a single IKEv2 profile and a single IPsec profile. The engineer wants to ensure that each spoke can authenticate using a unique pre-shared key. Which IKEv2 keyring configuration should be used on the hub?

⚠ Common exam trap

The trap here is thinking that multiple IKEv2 profiles or keyrings are required to support unique pre-shared keys per spoke, when a single keyring with multiple peer entries suffices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A single keyring with multiple peer entries, each specifying a different pre-shared key and matching the spoke's IP address.

FlexVPN supports a single IKEv2 keyring with multiple peer entries. Each peer entry can specify a unique pre-shared key and match criteria based on the spoke's identity, such as IP address or FQDN. The hub's IKEv2 profile references this keyring, and during IKEv2 authentication, the hub selects the appropriate key based on the peer's identity. This allows unique keys per spoke without needing multiple profiles or keyrings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A single keyring with multiple peer entries, each specifying the same pre-shared key but different identities.

    Why it's wrong here

    Using the same pre-shared key for all spokes does not provide unique keys. The identities can differ, but the key is shared, which violates the requirement. This approach is less secure and does not meet the design goal. Therefore, it is not correct.

  • ✗

    Multiple keyrings, each with a single peer entry, and multiple IKEv2 profiles referencing each keyring.

    Why it's wrong here

    While this would work, it is not the most efficient or scalable solution. FlexVPN is designed to use a single IKEv2 profile and keyring with multiple peer entries. Creating multiple profiles and keyrings increases configuration complexity and is unnecessary. The hub can match different spokes within a single keyring using peer entries. Thus, this is not the recommended configuration.

  • ✓

    A single keyring with multiple peer entries, each specifying a different pre-shared key and matching the spoke's IP address.

    Why this is correct

    In FlexVPN, the IKEv2 keyring can contain multiple peer entries, each with a different pre-shared key and a match statement for the spoke's identity (e.g., IP address). This allows the hub to use a unique key for each spoke while maintaining a single keyring. The IKEv2 profile references this keyring, and the hub selects the appropriate key based on the peer's identity. This is the correct and scalable approach.

  • ✗

    A single keyring with a single peer entry using a wildcard pre-shared key that matches all spokes.

    Why it's wrong here

    A wildcard pre-shared key would mean all spokes use the same key, which does not meet the requirement of unique keys per spoke. While it simplifies configuration, it reduces security because compromise of one key affects all spokes. The requirement explicitly states unique pre-shared keys, so this is incorrect.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.