mediumMultiple Choice
300-410 Practice Question: Runs the following command to verify crypto…
A network engineer runs the following command to verify crypto engine connections on a DMVPN spoke:
R2# show crypto engine connections active Crypto Engine Connections
ID Type Algorithm Encrypt Decrypt LastSeqN IP-Address 1 IPsec AES256-SHA 100 100 100 192.168.1.2
What does this output indicate?
⚠ Common exam trap
The trap here is assuming an empty or single-line output means no SAs exist, when in fact a single aggregated line with non-zero counters proves the tunnel is passing traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An IPsec SA is active with 100 packets encrypted and decrypted, indicating traffic flow.
The output shows an active IPsec SA with AES256-SHA as the encryption/integrity algorithm, and the Encrypt/Decrypt counters both at 100, meaning 100 packets have been encrypted and 100 decrypted — clear evidence of bidirectional traffic flow over the tunnel. The IP-Address 192.168.1.2 identifies the peer (the DMVPN hub or another spoke) for this SA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
No IPsec SAs are active; the connection list is empty.
Why it's wrong here
The table lists one active IPsec entry with AES256-SHA and non-zero encrypt/decrypt counters, so SAs clearly exist. An empty list would show only the header with no rows, which is not what this output displays.
- ✓
An IPsec SA is active with 100 packets encrypted and decrypted, indicating traffic flow.
Why this is correct
The table lists an active IPsec SA using AES256-SHA with matching encrypt and decrypt counters of 100, confirming bidirectional traffic is being protected. Equal counters indicate the tunnel is passing packets in both directions between the peers.
- ✗
The IPsec SA is failing due to algorithm mismatch.
Why it's wrong here
Encrypt and decrypt counters both read 100, showing traffic is passing successfully under AES256-SHA; a mismatch would prevent SA establishment and leave counters at zero. Algorithm mismatches appear as IKE or IPsec negotiation failures in debug and show crypto ipsec sa output.
- ✗
The connection is for IKE, not IPsec.
Why it's wrong here
The Type column reads IPsec, confirming this is an IPsec SA rather than an IKE SA. IKE entries would be listed with Type IKE, which is what you would check when troubleshooting Phase 1 negotiation problems.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.