Courseiva

300-410 · domain

VPN Technologies

VPN Technologies covers IPsec site-to-site and remote-access tunnels, DMVPN, FlexVPN, GET VPN, and IKEv1/IKEv2 negotiation on Cisco IOS and IOS XE routers. Questions are scenario-based: you pick protocols, match crypto map or profile parameters on both peers, read debug and show crypto output, and diagnose Phase 1 versus Phase 2 failures.

79 questions13 easy40 medium26 hard

Focused practice

Practice VPN Technologies questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about VPN Technologies

Be able to configure and verify IPsec, DMVPN, FlexVPN, and GET VPN on Cisco routers, and to isolate whether a tunnel failure is Phase 1 or Phase 2. The most important thing: confirm both peers agree on every IKE and IPsec parameter, including identity and proxy ACLs.

IKEv1/IKEv2 Phase 1 and Phase 2 parameter matching: encryption, hashing, DH group, lifetime, and pre-shared key or certificate authentication

IPsec crypto map, IPsec profile, and transform set configuration, including ACL or VTI-based interesting traffic selection

DMVPN Phase 1/2/3 with NHRP, mGRE, and tunnel protection, plus FlexVPN hub-and-spoke IKEv2 authorization

GET VPN group member and key server roles, including key distribution and the GDOI protocol

Watch out for

Common VPN Technologies exam traps

  • ▸Mismatched Phase 2 transform sets, proxy ACLs, or PFS settings between peers, which lets Phase 1 complete but makes Phase 2 fail with QM FSM errors.
  • ▸Assuming a single IKEv2 or IPsec profile can serve all spokes without matching authentication, authorization, or local/remote identity settings per peer.
  • ▸Confusing GET VPN key distribution with IKE: GDOI uses the key server, not standard IPsec IKE, to push encryption keys to group members.

Question index

All VPN Technologies questions (79)

Click any question to see the full explanation, or start a practice session above.

1

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) on a service provider MPLS network. The administrator must ensure that the group members can communicate securely while maintaining any-to-any connectivity and minimizing tunnel overhead. Which two statements about GET VPN are true? (Choose two.)

Hard
2

A network administrator is configuring a point-to-point GRE tunnel between two Cisco routers. The administrator wants to verify that the tunnel is operational and that the correct encapsulation is being used. Which command should be used to display the tunnel interface status, including the encapsulation and tunnel source/destination?

Easy
3

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which type of ACL should be used in the crypto map to match this traffic?

Medium
4

A network engineer is implementing FlexVPN with IKEv2 between a hub and multiple spokes. The hub uses a single IKEv2 profile and a single IPsec profile. The engineer wants to ensure that each spoke can authenticate using a unique pre-shared key. Which IKEv2 keyring configuration should be used on the hub?

Hard
5

A network administrator is deploying FlexVPN between a Cisco IOS headend and several remote spokes. The design requires that each spoke be assigned a unique virtual IP address from a pool on the headend, and that the headend pushes a specific DNS server address to each spoke during IKEv2 negotiation. Which configuration element on the headend provides the DNS server address to the spokes?

Hard
6

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. Phase 1 completes successfully, but Phase 2 fails. The administrator sees the log message 'QM FSM error' on the initiator. Which configuration mismatch is the most likely cause?

Hard
7

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the IPsec proposal. Which command would show the configured IPsec transform set and the algorithms being used?

Medium
8

A network engineer is configuring a DMVPN Phase 3 hub router. The hub must dynamically discover spoke-to-spoke tunnels while still using the hub for initial registration. Which technology allows the hub to redirect spoke traffic directly to another spoke?

Medium
9

A network engineer is configuring a VRF-aware IPsec VPN. The engineer needs to ensure that the IPsec tunnel traffic is forwarded within the correct VRF on the router. Which command must be configured under the crypto map to bind the IPsec tunnel to a specific VRF?

Medium
10

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers that uses IKEv2. Phase 1 is up, but Phase 2 fails. The administrator reviews the configuration and notices that the transform set on one router includes esp-aes 256 esp-sha256-hmac, while the other router has esp-aes 256 esp-sha512-hmac. The administrator wants to ensure the Phase 2 SA is established. Which action should the administrator take?

Medium
11

A network engineer is configuring a site-to-site DMVPN Phase 3 hub router. The hub uses a single mGRE tunnel interface with the IP address 10.0.0.1/24. Spoke routers are configured with NHS 10.0.0.1 and are in the same subnet. The engineer wants spoke-to-spoke traffic to bypass the hub after the initial resolution. Which command must be configured on the hub to enable Phase 3 shortcut switching?

Medium
12

A network engineer is deploying a GET VPN solution across a service provider MPLS network. The company requires that all group members use the same encryption keys and that any group member can decrypt traffic from any other group member. Which key distribution method should the engineer configure?

Medium
13

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router must advertise a default route to all spokes, but the spokes should not use the hub as the next hop for spoke-to-spoke traffic; instead, they should dynamically discover a direct path to other spokes. Which NHRP configuration on the hub is required to support this behavior?

Hard
14

A network technician is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but no traffic is passing. Which command should be used to verify that the tunnel source and destination are reachable?

Easy
15

A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?

Medium
16

A network engineer is configuring a GRE over IPsec tunnel between two Cisco IOS routers. The engineer wants to ensure that the GRE tunnel traffic is encrypted by IPsec. Which of the following configurations is required to achieve this?

Medium
17

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local subnet to the remote subnet is not passing. The administrator checks the crypto ACL and finds that it matches the traffic. Which of the following is the most likely cause of the problem?

Hard
18

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only specific traffic from the local subnet to the remote subnet is encrypted, while other traffic is sent in clear text. Which IPsec component is used to define the interesting traffic?

Easy
19

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers using IKEv2. Phase 1 is up, but Phase 2 fails to establish. The administrator runs 'show crypto ipsec sa' and sees no active SAs. Which action should the administrator take to resolve the issue?

Hard
20

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but the engineer cannot ping the remote tunnel endpoint. The physical interfaces are up, and there is a route to the remote physical address. Which command should be used to verify that the tunnel source and destination are correctly configured?

Medium
21

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes without requiring a full mesh of tunnels. Which technology should be implemented on the hub to allow spoke routers to resolve next-hop addresses directly?

Medium
22

A network administrator is building a FlexVPN hub-and-spoke deployment using IKEv2 on a Cisco IOS router. The hub must accept connections from many spokes that use dynamically assigned public addresses, and the administrator wants the hub to authorize each spoke and assign it an address from a pool after authentication. Which IKEv2 configuration element on the hub provides the address assignment to authenticated spokes?

Medium
23

A network engineer is deploying DMVPN Phase 3 with NHRP and wants spoke-to-spoke traffic to be built directly between spokes without traversing the hub after initial resolution. On the hub router, the engineer issues the command 'ip nhrp redirect' on the tunnel interface and 'ip nhrp shortcut' on each spoke tunnel interface. After configuration, spokes can reach the hub but spoke-to-spoke traffic still hairpins through the hub. Which additional configuration is required on the spoke routers for the shortcut path to be installed?

Medium
24

A network engineer is implementing GET VPN using GDOI on Cisco IOS routers. The key server must distribute the group policy, and the group members must register and receive rekey messages. The engineer needs to verify which components are required for the group members to successfully join the group and decrypt traffic. (Choose two.)

Hard
25

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers using IKEv1. Phase 1 completes successfully, but Phase 2 fails with the message 'QM_IDLE' and no IPSec SA is established. The administrator verifies that the transform sets on both peers contain matching encryption and hash algorithms. Which configuration mismatch is the most likely cause of the Phase 2 failure?

Medium
26

A network engineer is configuring DMVPN Phase 3 with IKEv2. The hub router is a Cisco IOS XE device, and the goal is to allow spoke-to-spoke traffic to bypass the hub after initial registration. Which command must be configured on the hub to enable NHRP redirects?

Medium
27

A network engineer is configuring a GRE tunnel over an IPsec VPN to support multicast traffic between two sites. The engineer notices that multicast traffic is not passing through the tunnel, although unicast traffic works. Which of the following is the most likely reason?

Medium
28

A network administrator is deploying DMVPN Phase 3 with IKEv2 between a hub and two spokes. The hub is configured with a dynamic multipoint VPN tunnel and uses NHRP. Spoke1 can reach Spoke2 via the hub, but direct spoke-to-spoke communication fails. The administrator verifies that NHRP registrations are successful and that the hub has routes to both spokes. Which action is most likely to enable direct spoke-to-spoke communication?

Hard
29

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The customer requires that traffic for the 10.1.1.0/24 subnet be encrypted, but all other traffic must be sent unencrypted. The engineer applies a crypto map to the outside interface. Which additional configuration is required to meet this requirement?

Medium
30

A network engineer is troubleshooting an IPsec VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The engineer runs `show crypto ipsec sa` and notices that the encaps/decaps counters are incrementing, but the inbound and outbound packets are being dropped. The ACL used for the VPN is `permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255`. What is the most likely cause of the dropped packets?

Medium
31

A network engineer is troubleshooting a site-to-site IPsec VPN that fails to establish. The engineer suspects that the pre-shared key is incorrect. Which command can be used to verify the pre-shared key configuration on a Cisco IOS router?

Easy
32

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spoke routers are behind dynamic NAT and cannot be reached directly. The engineer wants spoke-to-spoke traffic to bypass the hub after initial resolution. Which NHRP command on the spoke routers enables this behavior?

Medium
33

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly without traffic traversing the hub. Which command must be configured on the hub to enable spoke-to-spoke direct tunnels?

Medium
34

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?

Medium
35

A network administrator is setting up a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the VPN tunnel uses strong encryption and hashing algorithms. Which of the following should be configured to define the encryption and hashing algorithms used for the IPsec SA?

Easy
36

A network engineer is configuring a site-to-site IPsec VPN between two Cisco routers. The engineer wants to use a pre-shared key for authentication. Which command is used to configure the pre-shared key on the router?

Easy
37

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?

Hard
38

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology on Cisco IOS routers. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which command must be configured on the hub's tunnel interface to enable Phase 3 behavior?

Medium
39

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke deployment where the hub uses mGRE and spokes use mGRE. Spoke-to-spoke traffic works, but the administrator notices that the spokes are installing host routes for other spokes in their routing tables. Which DMVPN Phase 3 feature is responsible for adding these specific host routes?

Medium
40

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The engineer notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

Easy
41

A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?

Hard
42

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers. IKEv1 Phase 1 completes and the peer is authenticated, but the administrator sees that no IPsec SA is installed and interesting traffic is dropped. The administrator confirms the transform sets, ACLs, and pre-shared keys match on both sides. Which configuration element should the administrator verify next on both routers?

Hard
43

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke network using mGRE and NHRP. Spoke-to-spoke communication is failing, but spoke-to-hub communication works. The administrator verifies that NHRP registrations are successful and that the hub is configured with 'ip nhrp redirect'. What is the most likely cause of the spoke-to-spoke failure?

Hard
44

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that traffic from the 10.1.1.0/24 subnet is encrypted when going to the 10.2.2.0/24 subnet, but all other traffic should be sent unencrypted. Which configuration element is required to match this traffic?

Medium
45

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?

Hard
46

A network engineer is implementing DMVPN Phase 3 with IPsec tunnel protection. The hub router must be configured to support NHRP redirect. Which command is required on the hub's tunnel interface?

Hard
47

A network engineer is deploying a GET VPN solution using Cisco IOS routers. The key server must be configured to rekey group members. Which protocol does GET VPN use to distribute encryption keys and policies to group members?

Hard
48

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router is a Cisco IOS XE device running a recent release. The engineer notices that spoke-to-spoke traffic is still traversing the hub even though the spokes have established direct tunnels. Which technology must be enabled on the hub to allow spoke routers to dynamically discover a direct path to other spokes?

Medium
49

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. The VPN tunnel is up, but only small pings succeed; larger packets fail. The administrator suspects an MTU or fragmentation issue. Which action is most likely to resolve the problem while maintaining security?

Hard
50

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel only comes up when there is interesting traffic matching an extended ACL. The ACL is defined as: access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. The crypto map is applied to interface GigabitEthernet0/0. Which command is required to complete the configuration so that the router considers traffic matching the ACL as interesting?

Medium
51

A network administrator is troubleshooting a DMVPN Phase 3 configuration on a Cisco IOS router. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels; all traffic between spokes is going through the hub. The administrator verifies that NHRP registration is successful and that the hub has a mapping for each spoke. Which configuration change on the hub is required to enable spoke-to-spoke direct communication?

Hard
52

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?

Medium
53

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is GigabitEthernet0/0 on Router A with IP 192.168.1.1, and the tunnel destination is 192.168.2.1 on Router B. After configuration, the tunnel interface is up, but no traffic passes through. What is the most likely cause?

Easy
54

A router running Cisco IOS XE has a VRF-aware DMVPN phase 3 tunnel interface. The network administrator wants to ensure that spoke-to-spoke traffic is switched directly between spokes when a route to the destination is present in the NHRP database. Which configuration on the hub is required to enable this behavior?

Medium
55

A network architect is designing a FlexVPN solution using IKEv2 between a hub and multiple spokes. The hub must authenticate spokes using certificates, and spokes must authenticate the hub. The architect wants to ensure that the hub can verify the revocation status of spoke certificates in real time. Which mechanism should be implemented?

Hard
56

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes should be able to communicate directly with each other without traffic traversing the hub. The hub router interface is already configured with 'ip nhrp network-id 1' and 'ip nhrp map multicast dynamic'. Which additional command must be configured on the hub to allow spoke-to-spoke direct tunnels?

Medium
57

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the transform set. Which command should be used to verify the transform set configured for the crypto map on the local router?

Medium
58

A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?

Medium
59

A network engineer is deploying GET VPN across an MPLS L3VPN service provider network. The key server is reachable by all group members, and the engineer wants to avoid rekeying storms when many group members reboot simultaneously after a power outage. Which mechanism should the engineer configure on the key server to spread rekey retransmissions over a period of time?

Medium
60

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub has a public IP address and is reachable. Spokes are behind NAT devices and have dynamic public IP addresses. Which technology allows spokes to communicate directly without routing traffic through the hub?

Medium
61

A network engineer is deploying GET VPN with Cisco IOS routers to provide any-to-any encrypted communication over a private MPLS WAN. The design requires that a router joining the group automatically receives the current group security policy from the group controller without any manual pre-shared key configuration on the member. Which protocol should the engineer configure to dynamically distribute the group encryption keys from the key server to the group members?

Medium
62

A network administrator is deploying a GET VPN using Cisco IOS routers. The key server is configured with a cooperative key server (COOP) for redundancy. The administrator notices that some group members are not registering with the primary key server. Which protocol and port must be allowed through the firewall for the group members to register with the key server?

Hard
63

A network administrator is configuring DMVPN Phase 3 with a hub-and-spoke topology. The administrator wants to enable spoke-to-spoke communication directly without traversing the hub. Which command must be configured on the hub router to allow spoke-to-spoke tunnels?

Hard
64

A network engineer is deploying a GET VPN solution across an MPLS VPN WAN. The group members must encrypt traffic between any pair of sites without establishing point-to-point tunnels, and the key server must distribute a common encryption policy to all members. The engineer has configured the key server with a rekey policy but group members are not receiving rekeys. Which action must be taken on the key server to enable successful rekey transmission?

Medium
65

Which protocol should be used to dynamically distribute encryption keys for a GET VPN deployment?

Easy
66

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?

Medium
67

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS XE routers. The administrator wants to ensure that the VPN tunnel only encrypts traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet. Which configuration element defines the traffic to be encrypted?

Easy
68

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The tunnel is up, but traffic is not passing. The administrator runs show crypto ipsec sa and notices that the inbound and outbound ESP SAs are present, but the packet counters are not incrementing. The ACL used for the crypto map is permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. Which action is most likely to resolve the issue?

Hard
69

A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?

Medium
70

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP, and wants spokes to reach other spokes directly without routing through the hub for every packet. The engineer must configure the hub so that it advertises a default route to the spokes while still allowing spoke-to-spoke shortcut tunnels. (Choose two.)

Medium
71

A network engineer is implementing a DMVPN Phase 3 network with NHRP and mGRE on the hub. The design requires that spoke-to-spoke traffic be able to bypass the hub after resolution, and that the hub not be required to advertise specific routes to the spokes. Which two configuration elements are required to achieve shortcut switching and default-route-only behavior on the spokes? (Choose two.)

Hard
72

A network engineer is configuring a DMVPN Phase 3 network with mGRE and NHRP. The hub router must be able to dynamically learn spoke routes and advertise them to other spokes. Which two statements are true regarding the configuration of the hub to support spoke-to-spoke communication in DMVPN Phase 3? (Choose two.)

Medium
73

A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?

Hard
74

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 network to the 10.2.2.0/24 network is encrypted. Which type of ACL must be used in the crypto map to define the interesting traffic?

Easy
75

A network administrator is setting up a site-to-site VPN between two Cisco IOS routers and wants to use IKEv2 with certificate-based authentication. The administrator has already installed the identity certificate and the CA certificate on both routers. Which additional configuration is required on each router so that IKEv2 can validate the peer's certificate during the IKE_AUTH exchange?

Easy
76

A network administrator is troubleshooting a DMVPN Phase 3 network. Spokes register with the hub, and routing adjacencies are up. However, spoke-to-spoke traffic is not taking the optimal path; it still goes through the hub. The hub is configured with `ip nhrp redirect` and `ip nhrp map multicast dynamic`. The administrator verifies that the spokes have `ip nhrp shortcut` configured. What is the most likely cause?

Hard
77

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic is not passing through it. The engineer suspects a routing issue. Which command should be used to verify that the remote subnet is being routed through the tunnel interface?

Easy
78

A network engineer is deploying a site-to-site VPN between two Cisco IOS routers. The security policy requires that the peer identities be authenticated with certificates issued by an internal CA, and that the two peers negotiate a fresh keying channel for each new IKEv2 SA without relying on aggressive-mode pre-shared keys. Which IKEv2 configuration element must be present on both routers to satisfy the certificate-based authentication requirement?

Medium
79

A network engineer is deploying DMVPN Phase 3 with IPsec protection on a Cisco IOS router acting as a hub. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spoke routers can dynamically establish direct tunnels. Which two statements are true about this deployment? (Choose two.)

Hard

Frequently asked questions

What does the VPN Technologies domain cover on the 300-410 exam?
Be able to configure and verify IPsec, DMVPN, FlexVPN, and GET VPN on Cisco routers, and to isolate whether a tunnel failure is Phase 1 or Phase 2. The most important thing: confirm both peers agree on every IKE and IPsec parameter, including identity and proxy ACLs.
How many questions are in this domain?
This page lists all 79 VPN Technologies questions in the 300-410 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only VPN Technologies questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
enarsi ENARSI vpn technologies Practice Questions