Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to verify crypto…

A network engineer runs the following command to verify crypto engine connections on a DMVPN spoke:

R2# show crypto engine connections active

Crypto Engine Connections

ID Type Algorithm Encrypt Decrypt LastSeqN IP-Address 1 IPsec AES256-SHA 100 100 100 192.168.1.2

What does this output indicate?

⚠ Common exam trap

The trap here is assuming an empty or single-line output means no SAs exist, when in fact a single aggregated line with non-zero counters proves the tunnel is passing traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An IPsec SA is active with 100 packets encrypted and decrypted, indicating traffic flow.

The output shows an active IPsec SA with AES256-SHA as the encryption/integrity algorithm, and the Encrypt/Decrypt counters both at 100, meaning 100 packets have been encrypted and 100 decrypted — clear evidence of bidirectional traffic flow over the tunnel. The IP-Address 192.168.1.2 identifies the peer (the DMVPN hub or another spoke) for this SA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    No IPsec SAs are active; the connection list is empty.

    Why it's wrong here

    The table lists one active IPsec entry with AES256-SHA and non-zero encrypt/decrypt counters, so SAs clearly exist. An empty list would show only the header with no rows, which is not what this output displays.

  • ✓

    An IPsec SA is active with 100 packets encrypted and decrypted, indicating traffic flow.

    Why this is correct

    The table lists an active IPsec SA using AES256-SHA with matching encrypt and decrypt counters of 100, confirming bidirectional traffic is being protected. Equal counters indicate the tunnel is passing packets in both directions between the peers.

  • ✗

    The IPsec SA is failing due to algorithm mismatch.

    Why it's wrong here

    Encrypt and decrypt counters both read 100, showing traffic is passing successfully under AES256-SHA; a mismatch would prevent SA establishment and leave counters at zero. Algorithm mismatches appear as IKE or IPsec negotiation failures in debug and show crypto ipsec sa output.

  • ✗

    The connection is for IKE, not IPsec.

    Why it's wrong here

    The Type column reads IPsec, confirming this is an IPsec SA rather than an IKE SA. IKE entries would be listed with Type IKE, which is what you would check when troubleshooting Phase 1 negotiation problems.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.