300-410 VPN Technologies Practice Question
A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?
⚠ Common exam trap
The trap here is believing that configuring the same pre-shared key under the IKEv2 profile is sufficient, when the key must be defined in an IKEv2 keyring entry that matches the peer's identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key
Cisco IOS IKEv2 pre-shared key authentication relies on the IKEv2 keyring to look up the key associated with the peer's identity. The IKEv2 profile references the keyring, but the key itself must exist in a peer or subnet entry that matches the spoke. Because no AAA authentication is configured, the keyring is the only source of the key, so adding the spoke identity with the matching key fixes the IKE_AUTH failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key
Why this is correct
IKEv2 pre-shared key authentication on Cisco IOS requires the hub to match the peer's identity against an entry in the IKEv2 keyring, where the pre-shared key is defined per peer or per subnet. Without a matching keyring peer entry, the hub cannot retrieve the pre-shared key during IKE_AUTH even though the profile exists, and the exchange fails. Adding the spoke identity with the correct key resolves the failure.
- ✗
Configure a local AAA authorization list on the IKEv2 profile to authorize the spoke's group policy
Why it's wrong here
Local AAA authorization is used to assign group policies after authentication succeeds. The failure occurs during IKE_AUTH authentication, before authorization. Adding an authorization list does not supply the missing pre-shared key and would not change the authentication result, so it does not resolve the described failure.
- ✗
Bind the IKEv2 profile to a virtual template interface used for the spoke's virtual access interface
Why it's wrong here
Virtual template binding determines how the spoke's virtual access interface is cloned after the session is established. It has no role in retrieving the pre-shared key during IKE_AUTH. The authentication failure occurs before interface creation, so this change would not resolve the problem and could complicate the configuration.
- ✗
Enable RSA signature authentication on the IKEv2 profile so the hub can validate the spoke without a keyring
Why it's wrong here
RSA signature authentication needs certificates and trustpoints on both peers. The scenario states the spoke is not sending a certificate, so signature authentication cannot succeed. Switching the profile to RSA does not address the missing pre-shared key lookup and would introduce additional configuration that the spoke does not support.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.