Courseiva
VPN Technologies →hardMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?

⚠ Common exam trap

The trap here is believing that configuring the same pre-shared key under the IKEv2 profile is sufficient, when the key must be defined in an IKEv2 keyring entry that matches the peer's identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key

Cisco IOS IKEv2 pre-shared key authentication relies on the IKEv2 keyring to look up the key associated with the peer's identity. The IKEv2 profile references the keyring, but the key itself must exist in a peer or subnet entry that matches the spoke. Because no AAA authentication is configured, the keyring is the only source of the key, so adding the spoke identity with the matching key fixes the IKE_AUTH failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key

    Why this is correct

    IKEv2 pre-shared key authentication on Cisco IOS requires the hub to match the peer's identity against an entry in the IKEv2 keyring, where the pre-shared key is defined per peer or per subnet. Without a matching keyring peer entry, the hub cannot retrieve the pre-shared key during IKE_AUTH even though the profile exists, and the exchange fails. Adding the spoke identity with the correct key resolves the failure.

  • ✗

    Configure a local AAA authorization list on the IKEv2 profile to authorize the spoke's group policy

    Why it's wrong here

    Local AAA authorization is used to assign group policies after authentication succeeds. The failure occurs during IKE_AUTH authentication, before authorization. Adding an authorization list does not supply the missing pre-shared key and would not change the authentication result, so it does not resolve the described failure.

  • ✗

    Bind the IKEv2 profile to a virtual template interface used for the spoke's virtual access interface

    Why it's wrong here

    Virtual template binding determines how the spoke's virtual access interface is cloned after the session is established. It has no role in retrieving the pre-shared key during IKE_AUTH. The authentication failure occurs before interface creation, so this change would not resolve the problem and could complicate the configuration.

  • ✗

    Enable RSA signature authentication on the IKEv2 profile so the hub can validate the spoke without a keyring

    Why it's wrong here

    RSA signature authentication needs certificates and trustpoints on both peers. The scenario states the spoke is not sending a certificate, so signature authentication cannot succeed. Switching the profile to RSA does not address the missing pre-shared key lookup and would introduce additional configuration that the spoke does not support.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.