300-410 VPN Technologies Practice Question
A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the transform set. Which command should be used to verify the transform set configured for the crypto map on the local router?
⚠ Common exam trap
The trap here is selecting show crypto ipsec sa, which only shows active SAs and would be empty if Phase 2 fails, rather than checking the configuration with show crypto map.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show crypto map
To verify the transform set configured in a crypto map, the show crypto map command is used. It displays the crypto map entries, including the transform set name, peer, and ACL. This allows the engineer to confirm the local configuration and compare it with the remote peer to identify mismatches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
show crypto map
Why this is correct
The show crypto map command displays the crypto map configuration, including the transform set, peer, and ACL. It shows the transform set name configured for each crypto map entry, which is exactly what the engineer needs to verify. This command works regardless of Phase 2 status and is the correct choice for checking configuration.
- ✗
show crypto ipsec transform-set
Why it's wrong here
This command displays the configured transform sets, including encryption and integrity algorithms, but it does not show which transform set is applied to a crypto map. The engineer needs to see the crypto map configuration to confirm the transform set assigned to the map entry. Thus, this command alone is insufficient.
- ✗
show crypto isakmp sa
Why it's wrong here
The show crypto isakmp sa command shows the Phase 1 ISAKMP security associations, including the state (e.g., QM_IDLE) and peer. It does not display transform sets or any Phase 2 parameters. It is useful for verifying Phase 1 status but not for troubleshooting Phase 2 transform set mismatches.
- ✗
show crypto ipsec sa
Why it's wrong here
The show crypto ipsec sa command displays the current IPsec security associations, including the transform sets used, but only after Phase 2 is established. Since Phase 2 is failing, this command will not show the configured transform set. It is useful for verifying active SAs, not for checking configuration.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.