Courseiva

CCNA VPN Technologies Questions

75 of 79 questions · Page 1/2 · VPN Technologies · Answers revealed

1
Multi-Selecthard

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) on a service provider MPLS network. The administrator must ensure that the group members can communicate securely while maintaining any-to-any connectivity and minimizing tunnel overhead. Which two statements about GET VPN are true? (Choose two.)

Select 2 answers
A.GET VPN encapsulates packets in a new IP header, adding significant overhead.
B.GET VPN uses IKEv2 to establish point-to-point tunnels between all group members.
C.GET VPN requires a key server to distribute encryption keys and policies to group members.
D.GET VPN uses a group security association (GSA) to encrypt traffic between group members without point-to-point tunnels.
E.GET VPN provides encryption only for unicast traffic, not multicast.
AnswersC, D

The key server is a central component that manages group policies, generates and distributes keys, and authenticates group members. It uses the Group Domain of Interpretation (GDOI) protocol to securely send the GSA to members. Without a key server, group members cannot obtain the necessary keys to encrypt or decrypt traffic, making it a mandatory element in GET VPN deployments.

Why this answer

GET VPN uses a group security association managed by a key server, allowing any-to-any secure communication without per-peer tunnels. The key server distributes policies and keys via GDOI. This design preserves the original IP header for routing and supports both unicast and multicast, making it ideal for MPLS networks.

Exam trap

The trap here is assuming GET VPN uses point-to-point tunnels or encapsulates packets with a new IP header, when it actually uses a group SA and preserves the original header.

2
MCQeasy

A network administrator is configuring a point-to-point GRE tunnel between two Cisco routers. The administrator wants to verify that the tunnel is operational and that the correct encapsulation is being used. Which command should be used to display the tunnel interface status, including the encapsulation and tunnel source/destination?

A.show interfaces tunnel 0
B.show ip interface brief
C.show crypto ipsec sa
D.show ip route
AnswerA

The show interfaces tunnel 0 command displays detailed information about the tunnel interface, including its status, encapsulation (GRE/IP), source and destination addresses, and other parameters. This command is essential for verifying that the tunnel is up and configured correctly. It provides the necessary details to confirm operational status and encapsulation type.

Why this answer

The show interfaces tunnel 0 command provides comprehensive details about the tunnel interface, including its operational status, encapsulation type (GRE), and the configured tunnel source and destination. This allows the administrator to verify that the tunnel is up and correctly configured. The other commands do not provide the necessary tunnel-specific information.

Exam trap

The trap here is assuming that show ip interface brief provides enough detail, but it only shows IP addresses and status, not encapsulation or tunnel endpoints.

3
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which type of ACL should be used in the crypto map to match this traffic?

A.A standard ACL that permits the 10.1.1.0/24 subnet.
B.An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and denies all other traffic.
C.A named ACL that permits all IP traffic.
D.An extended ACL that denies IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and permits all other traffic.
AnswerB

This is correct because the crypto ACL defines interesting traffic that should be encrypted. It must permit the specific source/destination subnet pair and implicitly deny everything else. The implicit deny ensures other traffic is not encrypted, and the ACL is used to match traffic for the VPN.

Why this answer

The crypto ACL must permit the specific traffic that should be encrypted and implicitly deny all other traffic. An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24 and denies all other traffic achieves this. Standard ACLs cannot match destination addresses, and denying the desired traffic or permitting all traffic would be incorrect.

Exam trap

The trap here is confusing the direction of the ACL: the crypto ACL permits interesting traffic, not denies it.

4
MCQhard

A network engineer is implementing FlexVPN with IKEv2 between a hub and multiple spokes. The hub uses a single IKEv2 profile and a single IPsec profile. The engineer wants to ensure that each spoke can authenticate using a unique pre-shared key. Which IKEv2 keyring configuration should be used on the hub?

A.A single keyring with multiple peer entries, each specifying the same pre-shared key but different identities.
B.Multiple keyrings, each with a single peer entry, and multiple IKEv2 profiles referencing each keyring.
C.A single keyring with multiple peer entries, each specifying a different pre-shared key and matching the spoke's IP address.
D.A single keyring with a single peer entry using a wildcard pre-shared key that matches all spokes.
AnswerC

In FlexVPN, the IKEv2 keyring can contain multiple peer entries, each with a different pre-shared key and a match statement for the spoke's identity (e.g., IP address). This allows the hub to use a unique key for each spoke while maintaining a single keyring. The IKEv2 profile references this keyring, and the hub selects the appropriate key based on the peer's identity. This is the correct and scalable approach.

Why this answer

FlexVPN supports a single IKEv2 keyring with multiple peer entries. Each peer entry can specify a unique pre-shared key and match criteria based on the spoke's identity, such as IP address or FQDN. The hub's IKEv2 profile references this keyring, and during IKEv2 authentication, the hub selects the appropriate key based on the peer's identity.

This allows unique keys per spoke without needing multiple profiles or keyrings.

Exam trap

The trap here is thinking that multiple IKEv2 profiles or keyrings are required to support unique pre-shared keys per spoke, when a single keyring with multiple peer entries suffices.

5
MCQhard

A network administrator is deploying FlexVPN between a Cisco IOS headend and several remote spokes. The design requires that each spoke be assigned a unique virtual IP address from a pool on the headend, and that the headend pushes a specific DNS server address to each spoke during IKEv2 negotiation. Which configuration element on the headend provides the DNS server address to the spokes?

A.A crypto pki trustpoint that includes the DNS server in the certificate subject alternative name field.
B.An IKEv2 authorization policy that specifies the DNS server and is referenced by the IKEv2 profile.
C.A local IP pool configured with the ip local pool command and referenced under the virtual-template interface.
D.A dynamic routing protocol such as OSPF configured on the virtual-template interface to advertise the DNS server.
AnswerB

In FlexVPN, the IKEv2 authorization policy carries attributes such as the DNS server, the virtual IP pool, and the split-tunnel ACL that the headend pushes to the spoke. When the IKEv2 profile references the authorization policy, the headend can return the DNS server address in the IKE_AUTH exchange. This is the correct mechanism for delivering the requested DNS attribute to each spoke.

Why this answer

FlexVPN uses IKEv2 configuration attributes to deliver parameters such as virtual IP addresses, DNS servers, and split-tunnel information to spokes. The headend's IKEv2 authorization policy defines these attributes, and the IKEv2 profile references the authorization policy so the values are returned during IKE_AUTH. The local IP pool supplies addresses, but the DNS server specifically comes from the authorization policy, making it the correct element for the stated requirement.

Exam trap

The trap here is confusing the address-assignment pool with the attribute-delivery policy, so the engineer picks the pool for a value it does not carry.

6
MCQhard

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. Phase 1 completes successfully, but Phase 2 fails. The administrator sees the log message 'QM FSM error' on the initiator. Which configuration mismatch is the most likely cause?

A.Mismatched encryption algorithm in Phase 1
B.Mismatched DH group in Phase 1
C.Mismatched transform sets
D.Mismatched IKEv1 pre-shared keys
AnswerC

The QM FSM error during quick mode often indicates that the responder cannot find a matching transform set for the Phase 2 proposal. If the initiator offers a transform set that the responder does not support or has not configured, the responder may send a delete or fail to process the quick mode exchange, leading to the QM FSM error on the initiator.

Why this answer

A QM FSM error during Phase 2 typically points to a mismatch in the quick mode parameters, most commonly the transform set. The transform set defines the encryption and authentication algorithms for the IPsec SA. If the initiator proposes a transform set that the responder does not have configured or does not support, the responder may reject the proposal, causing the initiator to log a QM FSM error.

Verifying that both peers have identical transform sets resolves the issue.

Exam trap

The trap here is assuming that any mismatch causes Phase 1 failure; QM FSM error specifically indicates a Phase 2 negotiation problem, so focus on transform sets and other Phase 2 parameters.

7
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the IPsec proposal. Which command would show the configured IPsec transform set and the algorithms being used?

A.show crypto map
B.show crypto isakmp sa
C.show crypto ipsec sa
D.show crypto ipsec transform-set
AnswerD

The show crypto ipsec transform-set command lists all configured IPsec transform sets, including the name and the specific protocols and algorithms (e.g., esp-aes, esp-sha-hmac). This allows the engineer to compare the transform set on both routers and identify any mismatch in encryption or authentication algorithms that would cause Phase 2 negotiation to fail. It is the most direct way to verify the configured IPsec proposal.

Why this answer

When Phase 2 fails, the most likely cause is a mismatch in the IPsec transform set. The show crypto ipsec transform-set command reveals the configured algorithms for each transform set, enabling comparison between peers. While other commands show SA status or map references, only this command directly displays the transform set details needed to identify the mismatch.

Exam trap

The trap here is assuming that show crypto ipsec sa will show the configured transform set; it only shows established SAs, which may be absent when Phase 2 fails.

8
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub router. The hub must dynamically discover spoke-to-spoke tunnels while still using the hub for initial registration. Which technology allows the hub to redirect spoke traffic directly to another spoke?

A.NHRP shortcut
B.NHRP redirect
C.NHRP registration
D.NHRP resolution
AnswerB

NHRP redirect is a Phase 3 DMVPN feature where the hub sends an NHRP redirect message to the source spoke when it detects traffic that could be sent directly to another spoke. This enables the spoke to initiate an NHRP resolution for the destination spoke's NBMA address and build a direct tunnel, optimizing the path.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform a source spoke that a more optimal direct path exists to the destination spoke. The hub inspects incoming packets and, upon determining that the destination is reachable via another spoke, sends an NHRP redirect message. The source spoke then initiates NHRP resolution for the destination and establishes a direct spoke-to-spoke tunnel, achieving Phase 3 shortcuts.

Exam trap

The trap here is confusing NHRP redirect with NHRP shortcut; redirect is the hub's action to signal a better path, while shortcut is the spoke's action to use it.

9
MCQmedium

A network engineer is configuring a VRF-aware IPsec VPN. The engineer needs to ensure that the IPsec tunnel traffic is forwarded within the correct VRF on the router. Which command must be configured under the crypto map to bind the IPsec tunnel to a specific VRF?

A.set vrf VPN-CORP
B.set ip vrf VPN-CORP
C.ip vrf forwarding VPN-CORP
D.vrf forwarding VPN-CORP
AnswerA

The set vrf command under a crypto map entry specifies the VRF that the IPsec tunnel will use for forwarding. It ensures that the encrypted traffic is routed within the correct VRF, enabling VRF-aware IPsec. This is the correct command to bind the tunnel to a VRF.

Why this answer

To bind an IPsec tunnel to a VRF in a VRF-aware IPsec configuration, the set vrf command is used under the crypto map entry. This ensures that the tunnel's traffic is forwarded using the specified VRF's routing table, allowing overlapping address spaces and segmentation.

Exam trap

The trap here is confusing interface-level VRF commands like vrf forwarding with crypto map-level commands, leading to selecting the wrong syntax.

10
MCQmedium

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers that uses IKEv2. Phase 1 is up, but Phase 2 fails. The administrator reviews the configuration and notices that the transform set on one router includes esp-aes 256 esp-sha256-hmac, while the other router has esp-aes 256 esp-sha512-hmac. The administrator wants to ensure the Phase 2 SA is established. Which action should the administrator take?

A.Configure a matching transform set on both routers with the same encryption and integrity algorithms.
B.Change the IKEv2 proposal to use a different DH group.
C.Restart the IKEv2 process on both routers to clear the Phase 1 SA and force renegotiation.
D.Enable perfect forward secrecy on both routers by configuring the same DH group in the IPsec profile.
AnswerA

Phase 2 (IPsec SA) requires both peers to agree on the transform set, which specifies the encryption and integrity algorithms. The mismatch between esp-sha256-hmac and esp-sha512-hmac prevents the IPsec SA from being established. Configuring identical transform sets on both routers, such as esp-aes 256 esp-sha256-hmac, ensures both peers propose and accept the same algorithms, allowing Phase 2 to complete successfully.

Why this answer

IPsec Phase 2 requires both peers to agree on a transform set that defines the encryption and integrity algorithms. The mismatch between esp-sha256-hmac and esp-sha512-hmac means the peers cannot agree on the integrity algorithm, so the IPsec SA fails to establish. The administrator must configure a matching transform set on both routers, ensuring the encryption and integrity algorithms are identical, to allow Phase 2 to complete.

Exam trap

The trap here is assuming that Phase 2 failures are caused by Phase 1 parameters like DH group or IKEv2 proposal settings, rather than the transform set mismatch.

11
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub router. The hub uses a single mGRE tunnel interface with the IP address 10.0.0.1/24. Spoke routers are configured with NHS 10.0.0.1 and are in the same subnet. The engineer wants spoke-to-spoke traffic to bypass the hub after the initial resolution. Which command must be configured on the hub to enable Phase 3 shortcut switching?

A.ip nhrp shortcut
B.ip nhrp network-id 100
C.ip nhrp map multicast dynamic
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command on the hub enables NHRP redirect messages, which inform the originating spoke that a better path exists directly to the destination spoke. This triggers the spoke to send an NHRP resolution request for the destination's NBMA address, allowing the spoke to build a direct tunnel, which is the defining behavior of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect to send redirect messages to spokes when it forwards traffic to another spoke. The spokes must have ip nhrp shortcut to act on those redirects. Together, they allow spoke-to-spoke direct tunnels after initial hub-based resolution.

The hub's role is to redirect, so ip nhrp redirect is the correct command on the hub.

Exam trap

The trap here is confusing the hub-side and spoke-side commands, thinking that ip nhrp shortcut is configured on the hub when it is actually a spoke command.

12
MCQmedium

A network engineer is deploying a GET VPN solution across a service provider MPLS network. The company requires that all group members use the same encryption keys and that any group member can decrypt traffic from any other group member. Which key distribution method should the engineer configure?

A.Configure FlexVPN with IKEv2 and a single IPsec profile on the hub.
B.Configure DMVPN with NHRP and IPsec profiles on all routers.
C.Configure IKEv2 with a single pre-shared key on all group members.
D.Configure GDOI with a key server that distributes the Group Encryption Key and Group Anti-Replay key.
AnswerD

GDOI is the Group Domain of Interpretation protocol used by GET VPN. The key server distributes the Group Encryption Key (used for traffic encryption) and the Group Anti-Replay key to all group members, enabling any group member to decrypt traffic from any other member without direct IPsec tunnels between them.

Why this answer

GET VPN uses GDOI to distribute group keys from a key server to all group members. This allows any member to encrypt and decrypt traffic for any other member using the same Group Encryption Key and Group Anti-Replay key, without building point-to-point IPsec tunnels. IKEv2, DMVPN, and FlexVPN do not provide this group key distribution model.

Exam trap

The trap here is assuming that any IPsec keying protocol can distribute group keys, when only GDOI is designed for GET VPN group key management.

13
MCQhard

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router must advertise a default route to all spokes, but the spokes should not use the hub as the next hop for spoke-to-spoke traffic; instead, they should dynamically discover a direct path to other spokes. Which NHRP configuration on the hub is required to support this behavior?

A.ip nhrp shortcut
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp map multicast dynamic
AnswerB

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists directly to the destination spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's NBMA address. This enables spoke-to-spoke direct tunnels while the hub still advertises a default route, exactly as required.

Why this answer

DMVPN Phase 3 requires the hub to be configured with ip nhrp redirect on its mGRE interface. This allows the hub to send NHRP redirect messages to spokes when it forwards traffic between them, prompting the source spoke to resolve the destination spoke's NBMA address and build a direct tunnel. The spokes must also be configured with ip nhrp shortcut to use the redirect information.

This combination allows the hub to advertise a default route while still enabling dynamic spoke-to-spoke direct paths.

Exam trap

The trap here is reversing the roles of ip nhrp redirect and ip nhrp shortcut, placing the spoke-side command on the hub.

14
MCQeasy

A network technician is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but no traffic is passing. Which command should be used to verify that the tunnel source and destination are reachable?

A.show ip route
B.traceroute <tunnel destination IP>
C.ping <tunnel destination IP>
D.show interface tunnel 0
AnswerC

Pinging the tunnel destination IP verifies reachability to the remote tunnel endpoint's physical interface. If the ping fails, the tunnel cannot pass traffic because the underlying transport is down. This is the first step to confirm connectivity before troubleshooting the tunnel itself.

Why this answer

Pinging the tunnel destination IP is the most direct way to verify that the remote endpoint is reachable. If the ping succeeds, the underlying transport is working, and further troubleshooting can focus on the tunnel configuration. If it fails, the issue is in the transport network, not the tunnel itself.

Exam trap

The trap here is relying on the tunnel interface status to assume connectivity, when the tunnel can be up even if the destination is unreachable due to routing or filtering issues.

15
MCQmedium

A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?

A.The rekey mechanism only applies to the control plane and does not affect data plane encryption keys.
B.The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.
C.The rekey command is used to manually trigger a key rollover on the key server.
D.The rekey mechanism requires each group member to initiate a new registration with the key server.
AnswerB

In GET VPN, the key server manages the GDOI protocol and distributes encryption keys to group members. The `rekey` command configures the key server to send rekey messages, which contain new keys or policies, to group members. This ensures that group members can update their keys without re-registering, maintaining secure communication.

Why this answer

GET VPN uses GDOI for group key management. The key server sends rekey messages to group members to update encryption keys and policies. This allows scalable key distribution without re-registration.

The rekey command configures the key server's rekey behavior, including algorithms and lifetimes. It directly impacts data plane keys, ensuring secure and efficient key rollover.

Exam trap

The trap here is thinking that rekey requires re-registration or is only for control plane, when it actually pushes new data plane keys to members.

16
MCQmedium

A network engineer is configuring a GRE over IPsec tunnel between two Cisco IOS routers. The engineer wants to ensure that the GRE tunnel traffic is encrypted by IPsec. Which of the following configurations is required to achieve this?

A.The transform set must include the GRE protocol as the encapsulation mode.
B.The crypto map must be applied to the GRE tunnel interface instead of the physical interface.
C.The crypto ACL must permit IP traffic between the private networks that are routed over the GRE tunnel.
D.The crypto ACL must permit GRE traffic (protocol 47) between the tunnel source and destination IP addresses.
AnswerD

For GRE over IPsec, the crypto ACL must match the GRE packets, which are protocol 47. The ACL should permit GRE between the tunnel source and destination IPs. This ensures that the GRE-encapsulated packets are encrypted by IPsec. Without matching GRE, the tunnel traffic would not be encrypted.

Why this answer

In a GRE over IPsec configuration, the GRE tunnel encapsulates the private traffic, and then IPsec encrypts the GRE packets. Therefore, the crypto ACL must match GRE traffic (protocol 47) between the tunnel endpoints. This ensures that the entire GRE packet, including the original private IP packet, is encrypted.

Permitting the private IP traffic in the crypto ACL would cause IPsec to encrypt the private packets before GRE encapsulation, which is not desired.

Exam trap

The trap here is assuming that the crypto ACL should match the private traffic that traverses the GRE tunnel, but in GRE over IPsec, the crypto ACL must match the GRE protocol itself.

17
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local subnet to the remote subnet is not passing. The administrator checks the crypto ACL and finds that it matches the traffic. Which of the following is the most likely cause of the problem?

A.There is no route for the remote subnet pointing to the tunnel interface or next-hop.
B.The crypto map is applied to the wrong interface.
C.The crypto ACL is configured with the wrong source and destination addresses.
D.The transform set is mismatched between peers.
AnswerA

Even if the IPsec tunnel is up, traffic will not pass if the router does not have a route to the remote subnet via the tunnel. The crypto ACL defines interesting traffic, but without a proper route, packets are either dropped or sent via the default route, not encrypted. This is a common oversight in site-to-site VPN configurations.

Why this answer

In an IPsec site-to-site VPN, the tunnel can be up due to traffic from other sources or because the peers established it, but for specific traffic to pass, the router must have a route to the remote subnet pointing to the tunnel or the next-hop. Without this route, packets are not sent through the tunnel and may be dropped or routed elsewhere. The crypto ACL matching is necessary but not sufficient; routing is equally important.

Exam trap

The trap here is focusing solely on the crypto ACL and IPsec parameters while overlooking the need for a routing entry that directs traffic into the tunnel.

18
MCQeasy

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only specific traffic from the local subnet to the remote subnet is encrypted, while other traffic is sent in clear text. Which IPsec component is used to define the interesting traffic?

A.Crypto ACL
B.ISAKMP policy
C.Transform set
D.Crypto map
AnswerA

A crypto ACL (access control list) is used to define which traffic is protected by IPsec. It specifies the source and destination addresses and ports that should be encrypted. Traffic matching the ACL is sent through the IPsec tunnel, while traffic not matching is sent in clear text. This is the standard method to identify interesting traffic in Cisco IOS IPsec configurations.

Why this answer

The crypto ACL is the component that specifies the traffic to be encrypted by IPsec. It acts as a filter, and only packets permitted by the ACL are protected. The crypto map then references this ACL to apply the IPsec policy.

Other components like transform set and ISAKMP policy handle encryption algorithms and key negotiation, not traffic selection.

Exam trap

The trap here is confusing the role of the crypto map with the crypto ACL; the crypto map applies the policy, but the ACL defines the interesting traffic.

19
MCQhard

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers using IKEv2. Phase 1 is up, but Phase 2 fails to establish. The administrator runs 'show crypto ipsec sa' and sees no active SAs. Which action should the administrator take to resolve the issue?

A.Verify that the IKEv2 proposal matches on both peers.
B.Verify that the IPsec transform set or profile matches on both peers.
C.Ensure that the crypto ACL or IPsec profile matches the traffic to be encrypted.
D.Check that the IKEv2 keyring contains the correct pre-shared key.
AnswerB

Phase 2 failure often results from a mismatch in the IPsec transform set or profile, which defines the encryption and integrity algorithms for the data plane. If the transform sets do not match, the peers cannot agree on the IPsec SA parameters, and Phase 2 fails. Checking and aligning the transform set or profile on both routers is a critical troubleshooting step for this scenario.

Why this answer

Phase 2 failure with no active SAs typically indicates a mismatch in the IPsec transform set or profile. Since Phase 1 is up, IKEv2 parameters like the proposal and pre-shared key are correct. The crypto ACL defines interesting traffic but does not prevent SA establishment.

Therefore, verifying the transform set or profile match is the correct action.

Exam trap

The trap here is focusing on Phase 1 parameters like the IKEv2 proposal or keyring when Phase 1 is already established; Phase 2 failures usually stem from transform set mismatches.

20
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but the engineer cannot ping the remote tunnel endpoint. The physical interfaces are up, and there is a route to the remote physical address. Which command should be used to verify that the tunnel source and destination are correctly configured?

A.show ip route
B.show ip interface brief
C.show interfaces tunnel 0
D.show crypto session
AnswerC

'show interfaces tunnel 0' displays the tunnel interface status, including the source and destination addresses, and the tunnel protocol. It verifies that the tunnel source and destination are correctly configured and that the tunnel is up. If the tunnel is up but pings fail, it could be a routing issue over the tunnel.

Why this answer

The 'show interfaces tunnel 0' command displays detailed information about the tunnel interface, including the configured source and destination addresses, and the tunnel status. It is the most direct way to verify that the tunnel endpoints are correctly configured. Other commands do not show the tunnel source and destination.

Exam trap

The trap here is assuming that 'show ip interface brief' provides enough detail to verify tunnel endpoints, when it only shows the interface IP address (which may be the tunnel IP, not the source/destination).

21
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes without requiring a full mesh of tunnels. Which technology should be implemented on the hub to allow spoke routers to resolve next-hop addresses directly?

A.Configure OSPF network type as point-to-multipoint on all routers.
B.Implement IPsec tunnel protection on the hub only.
C.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
D.Use BGP route reflectors to distribute spoke routes.
AnswerC

NHRP redirect on the hub and NHRP shortcut on the spokes enable Phase 3 DMVPN. The hub sends redirect messages to spokes when traffic is received on the same tunnel interface, allowing the spoke to dynamically build a direct tunnel to the destination spoke. This reduces latency and hub load.

Why this answer

NHRP redirect on the hub and NHRP shortcut on the spokes are the defining features of DMVPN Phase 3. The hub uses redirect messages to inform spokes of a better path, and spokes use shortcut to create direct tunnels. This enables dynamic spoke-to-spoke communication without a full mesh, reducing latency and hub resource consumption.

Exam trap

The trap here is confusing DMVPN Phase 2 with Phase 3, assuming that any dynamic routing protocol or IPsec configuration alone can enable spoke-to-spoke tunnels without NHRP redirect and shortcut.

22
MCQmedium

A network administrator is building a FlexVPN hub-and-spoke deployment using IKEv2 on a Cisco IOS router. The hub must accept connections from many spokes that use dynamically assigned public addresses, and the administrator wants the hub to authorize each spoke and assign it an address from a pool after authentication. Which IKEv2 configuration element on the hub provides the address assignment to authenticated spokes?

A.An IKEv2 authorization policy that references a local or DHCP address pool
B.A transform set with the esp-aes esp-sha256-hmac algorithms applied to the virtual template
C.An NHRP map entry for each spoke pointing to the hub's tunnel address
D.A crypto map with the set peer dynamic command on the hub
AnswerA

In FlexVPN, the IKEv2 authorization policy defines what an authenticated peer is allowed to receive, including the address pool used to assign an IP address to the spoke's virtual access interface. The hub references this policy in the IKEv2 profile so that after successful authentication the spoke is authorized and receives an address. This is the correct element for post-authentication address assignment.

Why this answer

FlexVPN uses IKEv2 profiles and authorization policies to control what authenticated peers receive. The authorization policy references an address pool, either local or external via DHCP, and the hub assigns each spoke an address for its virtual access interface after authentication succeeds. This is the mechanism that provides dynamic addressing to spokes in a hub-and-spoke FlexVPN deployment.

Exam trap

The trap here is confusing DMVPN mechanisms such as NHRP or legacy crypto map options with FlexVPN's IKEv2 authorization policy, which is what actually assigns addresses to authenticated spokes.

23
MCQmedium

A network engineer is deploying DMVPN Phase 3 with NHRP and wants spoke-to-spoke traffic to be built directly between spokes without traversing the hub after initial resolution. On the hub router, the engineer issues the command 'ip nhrp redirect' on the tunnel interface and 'ip nhrp shortcut' on each spoke tunnel interface. After configuration, spokes can reach the hub but spoke-to-spoke traffic still hairpins through the hub. Which additional configuration is required on the spoke routers for the shortcut path to be installed?

A.Enable 'ip nhrp map multicast dynamic' on the spoke tunnel interfaces.
B.Enable 'ip nhrp network-id' with the same value on all spoke tunnel interfaces.
C.Ensure the routing protocol on the spokes has a route to the destination spoke's tunnel network, typically via a summary or default from the hub, so traffic triggers NHRP resolution.
D.Configure the tunnel interface with 'ip nhrp nhs <hub-NBMA>' so the spoke registers to the hub.
AnswerC

For NHRP shortcut to install a direct path, the spoke must have a route pointing to the destination prefix through the tunnel, causing the packet to trigger an NHRP resolution request. Without reachability to the destination spoke subnet (often via a hub summary or default route), no resolution is triggered and traffic continues to hairpin through the hub.

Why this answer

DMVPN Phase 3 shortcut switching requires the spoke to have a route covering the remote spoke prefix so that forwarded traffic triggers an NHRP resolution. The hub uses 'ip nhrp redirect' to notify spokes of a better path, and the spoke uses 'ip nhrp shortcut' to act on that notification. Without a route toward the destination spoke network, the spoke never originates the resolution and the shortcut never installs.

Exam trap

The trap here is assuming that enabling 'ip nhrp shortcut' and 'ip nhrp redirect' alone is sufficient, when the spoke still needs a route covering the destination spoke prefix to trigger resolution.

24
Multi-Selecthard

A network engineer is implementing GET VPN using GDOI on Cisco IOS routers. The key server must distribute the group policy, and the group members must register and receive rekey messages. The engineer needs to verify which components are required for the group members to successfully join the group and decrypt traffic. (Choose two.)

Select 2 answers
A.Group members must be configured with the group identity and a matching GDOI group configuration referencing the key server.
B.Group members must have a static VRF configured to isolate the GET VPN traffic from the global routing table.
C.Group members must be configured with the same ACL as the key server to define interesting traffic for the encryption policy.
D.Group members must have IKEv2 configured with a certificate authority to authenticate to the key server.
E.Group members must successfully complete GDOI registration with the key server to obtain the group's rekey and data encryption keys.
AnswersA, E

Each group member needs a 'crypto gdoi group' configuration that includes the group identity number and the key server address, plus a 'crypto map' or 'crypto gdoi' reference. Without this, the member cannot initiate registration with the key server or match the group policy, so it never receives the group keys and cannot decrypt GET VPN traffic.

Why this answer

GET VPN GDOI group members must be configured with the correct group identity and key server reference, and they must successfully register to receive the KEK and TEK from the key server. These two elements are fundamental: the local group configuration identifies which key server to contact, and successful registration provides the keys needed to decrypt the group's encrypted traffic. Authentication uses IKEv1 rather than IKEv2 with a CA, and the encryption ACL comes from the downloaded policy.

Exam trap

The trap here is assuming GET VPN requires IKEv2 with certificates and manual ACLs, when GDOI actually uses IKEv1 for registration and distributes the policy from the key server.

25
MCQmedium

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers using IKEv1. Phase 1 completes successfully, but Phase 2 fails with the message 'QM_IDLE' and no IPSec SA is established. The administrator verifies that the transform sets on both peers contain matching encryption and hash algorithms. Which configuration mismatch is the most likely cause of the Phase 2 failure?

A.The ISAKMP policy priority numbers are different on the two peers.
B.The crypto ACLs on the two peers do not mirror each other for the interesting traffic.
C.The IKEv1 aggressive mode is enabled on one peer but not the other.
D.The pre-shared keys on the two peers do not match.
AnswerB

In IKEv1 main mode, the Phase 2 quick mode negotiation uses the crypto ACL to identify the traffic to protect, and the proxy IDs must be mirror images. If the source and destination subnets are reversed or mismatched, the peers cannot agree on the IPSec SA selectors, causing quick mode to fail even though Phase 1 is up and transform sets match.

Why this answer

In IKEv1, Phase 2 quick mode negotiates the IPSec SA using proxy identities derived from the crypto ACLs. These ACLs must be mirror images between peers so that the source and destination selectors align. If they do not mirror each other, quick mode fails and no IPSec SA is created, even though Phase 1 is established and transform sets match.

Exam trap

The trap here is focusing on transform set mismatches or Phase 1 parameters when the symptom of a working Phase 1 with a failing Phase 2 points to proxy identity or ACL mirroring issues.

26
MCQmedium

A network engineer is configuring DMVPN Phase 3 with IKEv2. The hub router is a Cisco IOS XE device, and the goal is to allow spoke-to-spoke traffic to bypass the hub after initial registration. Which command must be configured on the hub to enable NHRP redirects?

A.ip nhrp map multicast dynamic
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

The 'ip nhrp redirect' command is required on the hub in DMVPN Phase 3 to enable NHRP redirect messages. When a spoke sends traffic to the hub for a destination behind another spoke, the hub replies with an NHRP redirect, allowing the spoke to initiate a direct tunnel to the destination spoke. This is a key component of Phase 3 along with 'ip nhrp shortcut' on the spokes.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirects to inform spokes about a better path to reach another spoke. The 'ip nhrp redirect' command on the hub enables this behavior. Combined with 'ip nhrp shortcut' on the spokes, it allows dynamic direct tunnels.

Without the redirect on the hub, spokes continue to route traffic through the hub even if a direct path exists.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', placing the spoke-side command on the hub.

27
MCQmedium

A network engineer is configuring a GRE tunnel over an IPsec VPN to support multicast traffic between two sites. The engineer notices that multicast traffic is not passing through the tunnel, although unicast traffic works. Which of the following is the most likely reason?

A.The IPsec transform set does not support multicast traffic.
B.The IPsec ACL is not permitting multicast traffic.
C.The GRE tunnel interface is not configured with a tunnel source and destination.
D.Multicast routing is not enabled on the tunnel interfaces or the physical interfaces.
AnswerD

For multicast traffic to traverse a GRE tunnel, multicast routing must be enabled on the tunnel interface and the physical interface carrying the tunnel. Additionally, an appropriate multicast routing protocol (e.g., PIM) must be configured. Without enabling multicast routing, the router will not forward multicast packets into or out of the tunnel, even though unicast works. This is the most likely cause.

Why this answer

Multicast traffic over a GRE tunnel requires multicast routing to be enabled on both the tunnel interface and the physical interface. Additionally, a multicast routing protocol like PIM must be configured. Without these, the router will not forward multicast packets, even though unicast traffic works.

The IPsec ACL typically permits GRE, so it does not need to match multicast directly.

Exam trap

The trap here is assuming that IPsec or the ACL is blocking multicast, when the real issue is the lack of multicast routing configuration on the tunnel and physical interfaces.

28
MCQhard

A network administrator is deploying DMVPN Phase 3 with IKEv2 between a hub and two spokes. The hub is configured with a dynamic multipoint VPN tunnel and uses NHRP. Spoke1 can reach Spoke2 via the hub, but direct spoke-to-spoke communication fails. The administrator verifies that NHRP registrations are successful and that the hub has routes to both spokes. Which action is most likely to enable direct spoke-to-spoke communication?

A.Configure the hub as a route reflector for BGP.
B.Disable split horizon on the hub's tunnel interface.
C.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
D.Configure the spokes to use the hub as the next-hop for all routes.
AnswerC

DMVPN Phase 3 requires NHRP redirect on the hub to inform spokes of a better path, and NHRP shortcut on the spokes to dynamically create direct tunnels. Without these, spokes continue to route through the hub. Enabling both features allows the spoke to resolve the remote spoke's NBMA address and build a direct GRE tunnel.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke tunnels are established through NHRP. The hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, and each spoke must have 'ip nhrp shortcut' to intercept traffic and initiate NHRP resolution for the destination spoke. Without these, spokes will continue to forward traffic through the hub even though NHRP registrations succeed.

Exam trap

The trap here is confusing DMVPN Phase 2 and Phase 3 requirements; Phase 3 specifically needs NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke tunnels.

29
MCQmedium

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The customer requires that traffic for the 10.1.1.0/24 subnet be encrypted, but all other traffic must be sent unencrypted. The engineer applies a crypto map to the outside interface. Which additional configuration is required to meet this requirement?

A.Configure an extended ACL that permits IP traffic from 10.1.1.0/24 to the remote subnet and apply it to the crypto map as the match address.
B.Configure a standard ACL that permits the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
C.Configure a route map that matches the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
D.Configure an extended ACL that denies IP traffic from 10.1.1.0/24 to the remote subnet and apply it as the match address.
AnswerA

The match address in a crypto map references an extended ACL that defines the traffic to be encrypted. Permitting only traffic from the local 10.1.1.0/24 to the remote subnet ensures that only that traffic is protected, while other traffic is sent unencrypted because it does not match the ACL.

Why this answer

The match address in a crypto map must reference an extended ACL that permits the traffic to be encrypted. Only traffic permitted by this ACL will be protected; all other traffic is sent unencrypted. Therefore, an extended ACL permitting the desired subnet is required.

Exam trap

The trap here is confusing standard ACLs with extended ACLs for crypto map match address, or reversing the permit/deny logic.

30
MCQmedium

A network engineer is troubleshooting an IPsec VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The engineer runs `show crypto ipsec sa` and notices that the encaps/decaps counters are incrementing, but the inbound and outbound packets are being dropped. The ACL used for the VPN is `permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255`. What is the most likely cause of the dropped packets?

A.There is a routing issue or reverse path forwarding (RPF) check failure for the decapsulated packets.
B.The IPsec SA is using the wrong transform set.
C.The crypto map is applied to the wrong interface.
D.The ACL is too restrictive and does not match the actual traffic.
AnswerA

When encaps/decaps counters increment but packets are dropped, the router is successfully decrypting the packets. However, if there is no route back to the source or if Unicast RPF fails, the router drops the packets. This is a common issue where the decrypted packet's source is not reachable via the same interface it arrived on, triggering RPF drop.

Why this answer

When IPsec encaps/decaps counters increment but packets are dropped, the router is encrypting and decrypting successfully. The drop likely occurs after decryption due to a routing or RPF check failure. The decrypted packet's source address must be reachable via the interface it arrived on; if not, Unicast RPF drops it.

This is a common troubleshooting scenario in IPsec VPNs.

Exam trap

The trap here is focusing on the ACL or transform set when the counters indicate encryption/decryption is working, overlooking post-decryption routing or RPF issues.

31
MCQeasy

A network engineer is troubleshooting a site-to-site IPsec VPN that fails to establish. The engineer suspects that the pre-shared key is incorrect. Which command can be used to verify the pre-shared key configuration on a Cisco IOS router?

A.show crypto isakmp sa
B.show running-config | include crypto isakmp key
C.show crypto isakmp key
D.show crypto isakmp policy
AnswerB

The command 'show running-config | include crypto isakmp key' filters the running configuration to display lines containing 'crypto isakmp key'. This will show the configured pre-shared key, including the key string and the peer address. This is the most direct way to verify the pre-shared key on a Cisco IOS router. Note that the key is displayed in clear text, so handle with care.

Why this answer

The correct answer is to use the 'show running-config | include crypto isakmp key' command. This command filters the running configuration to show only the lines that contain the pre-shared key configuration. It displays the key and the associated peer address, allowing the engineer to verify if the key matches on both ends.

Other commands like 'show crypto isakmp policy' or 'show crypto isakmp sa' provide information about Phase 1 and Phase 2 parameters but do not reveal the pre-shared key.

Exam trap

The trap here is assuming that there is a dedicated show command for pre-shared keys, when in fact you must inspect the running configuration.

32
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spoke routers are behind dynamic NAT and cannot be reached directly. The engineer wants spoke-to-spoke traffic to bypass the hub after initial resolution. Which NHRP command on the spoke routers enables this behavior?

A.ip nhrp redirect
B.ip nhrp map multicast dynamic
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerD

The ip nhrp shortcut command is configured on spoke routers in a DMVPN Phase 3 topology. When a spoke receives an NHRP redirect from the hub, the shortcut command allows it to dynamically create a direct mGRE tunnel to the destination spoke, bypassing the hub for subsequent packets. Without this command, the spoke would continue sending traffic through the hub even after receiving the redirect.

Why this answer

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists directly to another spoke. The spoke must have ip nhrp shortcut enabled to act on that redirect and install a direct tunnel. Together, these commands allow spoke-to-spoke traffic to bypass the hub after the initial packet flow, reducing latency and hub load.

Exam trap

The trap here is confusing the hub-side command ip nhrp redirect with the spoke-side command ip nhrp shortcut; both are required, but they are applied on different routers.

33
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly without traffic traversing the hub. Which command must be configured on the hub to enable spoke-to-spoke direct tunnels?

A.ip nhrp network-id 1
B.ip nhrp redirect
C.ip nhrp map multicast dynamic
D.ip nhrp shortcut
AnswerB

The ip nhrp redirect command on the hub enables NHRP redirect messages that inform spokes of a better path to reach another spoke directly. When a spoke sends traffic to the hub for a destination behind another spoke, the hub sends an NHRP redirect, prompting the spoke to initiate a direct tunnel. This is a key requirement for DMVPN Phase 3 spoke-to-spoke communication.

Why this answer

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect to send NHRP redirect messages to spokes when it receives traffic destined for another spoke. The spokes must also have ip nhrp shortcut to act on those redirects and establish direct tunnels. The redirect on the hub is essential for signaling the availability of a better path.

Exam trap

The trap here is confusing the hub and spoke roles, thinking that ip nhrp shortcut is configured on the hub when it is actually a spoke-side command.

34
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?

A.NHRP holdtime and registration
B.NHRP redirect and shortcut switching
C.NHRP server-only and client-only configuration
D.NHRP authentication and mapping
AnswerB

NHRP redirect allows the hub to inform the source spoke that a better path exists, and shortcut switching enables the spoke to build a direct tunnel to the destination spoke. This is the core of DMVPN Phase 3, where the hub sends a redirect message and the spoke initiates an NHRP resolution for the destination, creating a direct spoke-to-spoke tunnel.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to the destination. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, builds a direct mGRE tunnel. This reduces latency and hub load by allowing direct spoke-to-spoke traffic.

Exam trap

The trap here is confusing NHRP authentication or registration with the mechanisms that enable direct spoke-to-spoke tunnels, when redirect and shortcut switching are the actual features.

35
MCQeasy

A network administrator is setting up a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the VPN tunnel uses strong encryption and hashing algorithms. Which of the following should be configured to define the encryption and hashing algorithms used for the IPsec SA?

A.Transform set
B.ISAKMP policy
C.IKEv2 profile
D.Crypto map
AnswerA

A transform set defines the encryption and hashing algorithms (e.g., esp-aes 256 and esp-sha-hmac) that will be used to protect the data. It is referenced by the crypto map or IPsec profile. This is the correct place to specify the algorithms for the IPsec SA. The transform set ensures both peers agree on the security parameters.

Why this answer

The transform set is used to define the encryption and hashing algorithms for the IPsec SA. It is referenced by the crypto map or IPsec profile. The ISAKMP policy defines Phase 1 parameters, while the crypto map and IKEv2 profile are used for other purposes.

Therefore, the transform set is the correct answer.

Exam trap

The trap here is confusing IKE Phase 1 parameters (defined in ISAKMP policy) with IPsec Phase 2 parameters (defined in transform set).

36
MCQeasy

A network engineer is configuring a site-to-site IPsec VPN between two Cisco routers. The engineer wants to use a pre-shared key for authentication. Which command is used to configure the pre-shared key on the router?

A.crypto ipsec key MYKEY
B.crypto isakmp key MYKEY address 192.168.1.1
C.crypto isakmp policy 10 authentication pre-share
D.crypto map MYMAP 10 set peer 192.168.1.1
AnswerB

The 'crypto isakmp key' command is used to configure a pre-shared key for IKE authentication. It specifies the key string and the peer's IP address. In this scenario, the peer is 192.168.1.1. This command is part of the ISAKMP policy configuration and is required for Phase 1 authentication when using pre-shared keys. It must be configured on both peers with matching keys.

Why this answer

Pre-shared key authentication in IKE is configured using the 'crypto isakmp key' command, which specifies the key and the peer address. This command is separate from the ISAKMP policy that defines the authentication method. Both peers must have the same pre-shared key for Phase 1 to succeed.

The key is used during the IKE authentication exchange.

Exam trap

The trap here is confusing the ISAKMP policy command that sets the authentication method with the command that actually configures the pre-shared key.

37
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?

A.show access-lists
B.show crypto ipsec sa
C.show crypto isakmp sa
D.show crypto map
AnswerA

'show access-lists' displays the configured ACLs and their hit counters. By examining the crypto ACL referenced in the crypto map, you can see if the counters are incrementing for the interesting traffic. If the counters are not incrementing, the ACL may not match the traffic, indicating a mismatch. This is a key step in troubleshooting IPsec VPNs when the tunnel is up but traffic is not flowing.

Why this answer

When an IPsec tunnel is up but traffic is not passing, a common cause is a mismatch between the crypto ACL and the actual traffic. The crypto ACL defines interesting traffic that should be encrypted. By using 'show access-lists', you can see if the ACL's permit entries are being hit by the traffic.

If counters are not incrementing, the traffic is not matching the ACL, and you need to adjust it.

Exam trap

The trap here is assuming that 'show crypto ipsec sa' alone can confirm ACL matches, but it only shows encrypted packets, not the ACL hit counters.

38
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology on Cisco IOS routers. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which command must be configured on the hub's tunnel interface to enable Phase 3 behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp network-id 1
C.ip nhrp shortcut
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command on the hub enables NHRP redirect messages, which notify spokes of a better path to another spoke, allowing direct spoke-to-spoke tunnels. This is a key requirement for DMVPN Phase 3. Without it, spokes continue to route through the hub. It works with ip nhrp shortcut on spokes to achieve dynamic spoke-to-spoke connectivity.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes about a more optimal path to another spoke, and spokes use NHRP shortcut to install a direct route. The hub must have ip nhrp redirect configured on its tunnel interface. The other options are either spoke-side commands or general NHRP parameters that do not enable Phase 3 behavior.

Exam trap

The trap here is confusing the hub-side redirect command with the spoke-side shortcut command, which are complementary but configured on different routers.

39
MCQmedium

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke deployment where the hub uses mGRE and spokes use mGRE. Spoke-to-spoke traffic works, but the administrator notices that the spokes are installing host routes for other spokes in their routing tables. Which DMVPN Phase 3 feature is responsible for adding these specific host routes?

A.ip nhrp registration no-unique on the spokes
B.ip nhrp map multicast dynamic on the hub
C.NHRP shortcut on the spokes
D.NHRP redirect on the hub
AnswerC

With NHRP shortcut, the spoke installs a host route for the destination spoke tunnel address after successful NHRP resolution. This route points at the tunnel interface and allows the spoke to send traffic directly to the peer, bypassing the hub. The host routes observed in the routing table are the visible result of NHRP shortcut operation.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform a spoke that a better path exists, and the spokes use NHRP shortcut to resolve the destination and install a host route for the peer tunnel address. Those host routes are what let the spoke forward traffic directly to another spoke. Without NHRP shortcut on the spokes, the redirect messages would not result in usable direct paths.

Exam trap

The trap here is confusing the hub-side redirect trigger with the spoke-side shortcut that actually installs the host route in the routing table.

40
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The engineer notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

A.The tunnel key is mismatched.
B.The tunnel destination is not reachable.
C.The tunnel mode is set to GRE multipoint.
D.The tunnel source and destination are reversed.
AnswerB

For a GRE tunnel to come up, the tunnel destination must be reachable via the underlay network. If the destination is not reachable, the tunnel interface will show up, but line protocol will be down. The engineer should verify routing to the tunnel destination and ensure that the loopback interface is advertised and reachable. This is a common issue when the underlay routing is misconfigured.

Why this answer

A GRE tunnel interface will show up/up only if the tunnel source is valid and the tunnel destination is reachable. If the destination is unreachable, the interface remains up but the line protocol goes down. The fix is to ensure that the underlay network has a route to the tunnel destination, often by advertising the loopback interface into the routing protocol or configuring a static route.

Exam trap

The trap here is assuming that a mismatched tunnel key or reversed endpoints cause the line protocol to drop, when in fact reachability of the tunnel destination is the key factor.

41
MCQhard

A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?

A.IPsec must be configured on the physical interfaces of the spokes.
B.A single IPsec profile on the hub and spokes can protect both hub-to-spoke and spoke-to-spoke traffic.
C.IPsec encryption for spoke-to-spoke traffic requires a separate IPsec profile on each spoke.
D.Spoke-to-spoke traffic bypasses IPsec encryption because it does not traverse the hub.
AnswerB

In DMVPN Phase 3, a single IPsec profile applied to the tunnel interface on all routers can secure both hub-to-spoke and spoke-to-spoke traffic. The dynamic multipoint tunnels are established on demand, and the same IPsec profile is used because the tunnel interface is the encryption endpoint. This simplifies configuration and is a key advantage of DMVPN with IPsec.

Why this answer

In DMVPN Phase 3, the same IPsec profile applied to the multipoint GRE tunnel interface on all routers (hub and spokes) protects all traffic, including spoke-to-spoke. When a spoke initiates a direct tunnel to another spoke, the IPsec session is established using the same profile. This uniform configuration is a primary benefit of DMVPN, allowing scalable and secure any-to-any connectivity.

Exam trap

The trap here is thinking that spoke-to-spoke traffic, because it bypasses the hub, also bypasses IPsec encryption, when in fact the encryption is applied at the tunnel interface on each spoke.

42
MCQhard

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers. IKEv1 Phase 1 completes and the peer is authenticated, but the administrator sees that no IPsec SA is installed and interesting traffic is dropped. The administrator confirms the transform sets, ACLs, and pre-shared keys match on both sides. Which configuration element should the administrator verify next on both routers?

A.The crypto map sequence numbers and the ACL referenced by each map
B.The IKEv1 Phase 1 lifetime values on each peer
C.The routing table entries for the remote protected subnet
D.The Phase 2 proposal parameters, including encryption, hash, and PFS group
AnswerD

Phase 2 requires both peers to agree on a matching IPsec proposal: encryption algorithm, hash or integrity algorithm, and, if perfect forward secrecy is configured, the Diffie-Hellman group. If any of these differ, the responder rejects the quick mode exchange and no IPsec SA is created even though Phase 1 is up. Verifying the proposal on both routers is the correct next step for this symptom.

Why this answer

When IKE Phase 1 succeeds but no IPsec SA appears, the failure is almost always in the Phase 2 exchange. Both peers must agree on identical IPsec proposal parameters: encryption, integrity or hash, and the PFS Diffie-Hellman group if enabled. A single mismatch in any of these causes the responder to reject quick mode, leaving Phase 1 up while interesting traffic is dropped.

Exam trap

The trap here is focusing on Phase 1 settings such as lifetime or identity, when a completed Phase 1 with no SA points squarely at mismatched Phase 2 proposal parameters.

43
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke network using mGRE and NHRP. Spoke-to-spoke communication is failing, but spoke-to-hub communication works. The administrator verifies that NHRP registrations are successful and that the hub is configured with 'ip nhrp redirect'. What is the most likely cause of the spoke-to-spoke failure?

A.The hub is missing 'ip nhrp map multicast dynamic'.
B.The hub is not configured with 'ip nhrp redirect'.
C.The spokes are not configured with 'ip nhrp shortcut'.
D.The spokes are not configured with 'ip nhrp network-id'.
AnswerC

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform spokes of a better path, but the spokes must have 'ip nhrp shortcut' to dynamically create a direct tunnel to the destination spoke. Without it, spokes continue to send traffic through the hub, and spoke-to-spoke communication fails to optimize.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication requires the hub to send NHRP redirect messages and the spokes to have 'ip nhrp shortcut' configured. The shortcut allows spokes to dynamically create direct tunnels upon receiving a redirect. Without it, spokes continue to route through the hub, and direct spoke-to-spoke communication does not occur.

Exam trap

The trap here is assuming that 'ip nhrp redirect' on the hub is sufficient; the spokes must also have 'ip nhrp shortcut'.

44
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that traffic from the 10.1.1.0/24 subnet is encrypted when going to the 10.2.2.0/24 subnet, but all other traffic should be sent unencrypted. Which configuration element is required to match this traffic?

A.A standard ACL with source 10.1.1.0 0.0.0.255, applied to the crypto map.
B.An extended ACL with source 10.1.1.0 0.0.0.255 and destination 10.2.2.0 0.0.0.255, referenced in the crypto map.
C.A prefix list that permits the 10.1.1.0/24 and 10.2.2.0/24 prefixes, referenced in the crypto map.
D.A route map that matches the source and destination subnets, applied to the crypto map.
AnswerB

This extended ACL precisely defines the interesting traffic that should be encrypted by the IPsec VPN. The source and destination addresses with wildcard masks match the specified subnets. Referencing it in the crypto map ensures only this traffic triggers the VPN tunnel, while other traffic is sent unencrypted, as required.

Why this answer

IPsec site-to-site VPNs use extended ACLs to define which traffic is encrypted. The ACL must match source and destination addresses of the traffic that should be protected. The ACL is referenced in the crypto map with the match address command.

Other traffic not matched by the ACL is sent in clear text. Standard ACLs, route maps, and prefix lists are not used for this purpose.

Exam trap

The trap here is confusing ACL types or thinking that any traffic-matching mechanism can be used in a crypto map, when only extended ACLs are valid for defining IPsec interesting traffic.

45
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?

A.The transform set is misconfigured with mismatched encryption algorithms.
B.The crypto map is applied to the wrong interface.
C.The IPsec SA lifetime is set to a lower value than the ISAKMP SA lifetime.
D.NAT is translating the traffic before it is encrypted, causing the IPsec peer to drop the packets.
AnswerD

If NAT is applied to the outbound interface before the crypto map, the source IP of the packets may be translated to the router's public IP, which does not match the crypto ACL. The IPsec peer will then drop the packets because they do not match the expected source subnet. This is a common issue when NAT and IPsec are configured on the same interface. The solution is to configure NAT exemption for the VPN traffic.

Why this answer

When NAT and IPsec are configured on the same router, outbound traffic may be translated by NAT before it is encrypted. If the translated source address does not match the crypto ACL, the remote peer will drop the packets because they do not match the interesting traffic. The tunnel remains up because Phase 1 and Phase 2 SAs are established, but data traffic fails.

The fix is to configure a NAT exemption (deny statement) for the VPN traffic in the NAT ACL.

Exam trap

The trap here is assuming that a successful tunnel establishment guarantees data flow; NAT can silently break IPsec by altering packets before encryption.

46
MCQhard

A network engineer is implementing DMVPN Phase 3 with IPsec tunnel protection. The hub router must be configured to support NHRP redirect. Which command is required on the hub's tunnel interface?

A.ip nhrp shortcut
B.ip nhrp network-id 1
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command enables the hub to send NHRP redirect messages to spokes when it receives traffic on the same tunnel interface. This is essential for Phase 3 DMVPN, allowing spokes to learn a better path and build direct tunnels. Without it, spokes continue to route through the hub.

Why this answer

The ip nhrp redirect command on the hub's tunnel interface is required for DMVPN Phase 3. It allows the hub to inform spokes about a better path when traffic is received on the same interface, prompting the spoke to initiate a direct tunnel. Without this command, the hub cannot send redirect messages, and spoke-to-spoke tunnels will not form dynamically.

Exam trap

The trap here is confusing the commands used on the hub versus the spokes; ip nhrp shortcut is for spokes, while ip nhrp redirect is for the hub.

47
MCQhard

A network engineer is deploying a GET VPN solution using Cisco IOS routers. The key server must be configured to rekey group members. Which protocol does GET VPN use to distribute encryption keys and policies to group members?

A.Group Domain of Interpretation (GDOI)
B.Group Key Management Protocol (GKMP)
C.Multicast Group Management Protocol (MGMP)
D.Internet Key Exchange version 2 (IKEv2)
AnswerA

GDOI is the protocol used by GET VPN to distribute encryption keys and policies from the key server to group members. It operates over UDP port 848 and allows the key server to push rekey messages, ensuring all group members share the same security policy and keys. GDOI is essential for the scalable any-to-any communication that GET VPN provides.

Why this answer

GET VPN uses the Group Domain of Interpretation (GDOI) protocol to distribute encryption keys and policies from the key server to group members. GDOI enables scalable group key management, allowing the key server to send rekey messages to all members. IKEv2 is for point-to-point VPNs, and the other options are not used for GET VPN key distribution.

Exam trap

The trap here is confusing IKEv2, which is used for point-to-point IPsec, with GDOI, which is specifically for group key management in GET VPN.

48
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router is a Cisco IOS XE device running a recent release. The engineer notices that spoke-to-spoke traffic is still traversing the hub even though the spokes have established direct tunnels. Which technology must be enabled on the hub to allow spoke routers to dynamically discover a direct path to other spokes?

A.Enable OSPF point-to-multipoint on the hub.
B.Enable NHRP redirect on the hub.
C.Enable NHRP shortcut on the hub.
D.Enable IPsec tunnel protection on the hub.
AnswerB

NHRP redirect on the hub informs the originating spoke that a better path exists to the destination spoke. The hub sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's NBMA address. This enables the spoke to build a direct tunnel, bypassing the hub for subsequent packets.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a source spoke that a more optimal path exists to a destination spoke. The spoke must have NHRP shortcut enabled to act on the redirect and initiate direct tunnel creation. Together, they allow dynamic spoke-to-spoke tunnels without preconfiguration.

Exam trap

The trap here is confusing NHRP redirect (hub) with NHRP shortcut (spoke), assuming either alone enables direct spoke-to-spoke tunnels.

49
MCQhard

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. The VPN tunnel is up, but only small pings succeed; larger packets fail. The administrator suspects an MTU or fragmentation issue. Which action is most likely to resolve the problem while maintaining security?

A.Adjust the tunnel interface MTU and TCP MSS clamping on the tunnel interface.
B.Enable path MTU discovery (PMTUD) on the tunnel and rely on ICMP unreachable messages.
C.Increase the IP MTU on the physical interface to accommodate larger packets.
D.Disable IPsec encryption on the tunnel to eliminate overhead.
AnswerA

Lowering the tunnel interface MTU and configuring TCP MSS clamping ensures that packets are sized appropriately before encryption and encapsulation, preventing fragmentation or drops. This maintains security because the packets are still encrypted and encapsulated correctly. It is a standard best practice for IPsec VPNs to account for the additional overhead of IPsec and GRE headers, especially when the underlying path has a lower MTU.

Why this answer

IPsec and GRE encapsulation add overhead, reducing the effective MTU. When large packets are sent, they may exceed the path MTU and get dropped if fragmentation is not allowed. Adjusting the tunnel interface MTU and configuring TCP MSS clamping ensures that TCP sessions negotiate a smaller MSS, preventing fragmentation and packet loss while keeping the VPN secure.

Exam trap

The trap here is assuming that enabling PMTUD alone will fix the issue, but ICMP filtering often breaks PMTUD, making manual MTU and MSS adjustments necessary.

50
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel only comes up when there is interesting traffic matching an extended ACL. The ACL is defined as: access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. The crypto map is applied to interface GigabitEthernet0/0. Which command is required to complete the configuration so that the router considers traffic matching the ACL as interesting?

A.match address 100
B.crypto map mymap 10 ipsec-isakmp
C.crypto isakmp policy 10
D.set peer 203.0.113.2
AnswerA

Within the crypto map configuration, the match address command specifies the extended ACL that defines interesting traffic. This ACL determines which packets are encrypted and sent through the tunnel. Here, match address 100 tells the router that traffic between 10.1.1.0/24 and 10.2.2.0/24 should be protected by IPsec, triggering the tunnel when such traffic is encountered.

Why this answer

The match address command within the crypto map entry binds the extended ACL to the crypto map, designating the traffic that should be protected by IPsec. In this scenario, the ACL 100 defines the interesting traffic between the two subnets. Without this command, the router would not know which packets to encrypt and tunnel, and the VPN would not initiate as intended.

Exam trap

The trap here is confusing the creation of the crypto map with the assignment of interesting traffic, assuming that defining the ACL alone is enough or that the peer command triggers the tunnel.

51
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 configuration on a Cisco IOS router. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels; all traffic between spokes is going through the hub. The administrator verifies that NHRP registration is successful and that the hub has a mapping for each spoke. Which configuration change on the hub is required to enable spoke-to-spoke direct communication?

A.Configure the tunnel interface with ip nhrp shortcut.
B.Configure the tunnel interface with ip nhrp map multicast dynamic.
C.Configure the tunnel interface with ip nhrp network-id 100.
D.Configure the tunnel interface with ip nhrp redirect.
AnswerD

In DMVPN Phase 3, the ip nhrp redirect command on the hub enables the hub to send NHRP redirect messages to spokes when it receives traffic that could be sent directly between spokes. This prompts the originating spoke to send an NHRP resolution request for the destination spoke's public IP, allowing a direct tunnel to be built. Without this, spoke-to-spoke traffic continues to traverse the hub.

Why this answer

In DMVPN Phase 3, spoke-to-spoke direct tunnels are facilitated by NHRP redirects from the hub and NHRP shortcuts on spokes. The hub must be configured with ip nhrp redirect to send redirect messages when it detects traffic between spokes that could be direct. This triggers the originating spoke to request the destination spoke's NBMA address and build a direct tunnel, offloading traffic from the hub.

Exam trap

The trap here is confusing the roles of ip nhrp redirect and ip nhrp shortcut, or applying the shortcut command on the hub instead of the spokes.

52
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?

A.ip nhrp network-id 1
B.ip nhrp shortcut
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command on the hub enables the hub to send a redirect message to the originating spoke when it detects that traffic is being routed through the hub to another spoke. This allows the spoke to initiate a direct NHRP resolution for the destination spoke's NBMA address, enabling spoke-to-spoke tunnels. Without redirect, spokes would continue to use the hub for all inter-spoke traffic.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes that a more optimal path exists directly to another spoke. The hub sends an NHRP redirect message to the source spoke, which then triggers an NHRP resolution for the destination spoke's NBMA address. The spoke then establishes a direct tunnel.

The hub must have ip nhrp redirect enabled, while spokes typically have ip nhrp shortcut to act on the redirect.

Exam trap

The trap here is confusing the roles of NHRP redirect and shortcut: redirect is configured on the hub to signal spokes, while shortcut is configured on spokes to create direct tunnels.

53
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is GigabitEthernet0/0 on Router A with IP 192.168.1.1, and the tunnel destination is 192.168.2.1 on Router B. After configuration, the tunnel interface is up, but no traffic passes through. What is the most likely cause?

A.The tunnel source and destination are in different subnets.
B.The tunnel mode is set to GRE/IPv4, which is not supported.
C.The tunnel interface is missing an IP address.
D.The tunnel destination is not reachable via the underlay network.
AnswerD

For a GRE tunnel to pass traffic, the tunnel destination IP address must be reachable through the underlay network. If the destination is not reachable, the tunnel interface may still show up if keepalives are not configured, but packets will be dropped because they cannot be encapsulated and sent. Ensuring reachability via a route or directly connected network is essential.

Why this answer

A GRE tunnel requires the tunnel destination to be reachable via the underlay network. If the destination is not reachable, the tunnel interface may appear up, but encapsulated packets cannot be delivered, resulting in no traffic flow. Other options are either incorrect or would cause different symptoms.

Ensuring underlay reachability and proper routing is essential for GRE tunnel operation.

Exam trap

The trap here is assuming that a tunnel interface being up means the tunnel is fully operational, when in fact it can be up even if the underlay destination is unreachable.

54
MCQmedium

A router running Cisco IOS XE has a VRF-aware DMVPN phase 3 tunnel interface. The network administrator wants to ensure that spoke-to-spoke traffic is switched directly between spokes when a route to the destination is present in the NHRP database. Which configuration on the hub is required to enable this behavior?

A.ip nhrp network-id 1
B.ip nhrp shortcut
C.ip nhrp redirect
D.ip nhrp map multicast dynamic
AnswerC

The ip nhrp redirect command on the hub enables NHRP redirect messages to be sent to spokes when traffic arrives at the hub for a destination that is reachable via another spoke. This allows the ingress spoke to learn an optimal path and initiate a direct spoke-to-spoke tunnel, which is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, spoke-to-spoke traffic optimization relies on the hub sending NHRP redirect messages to the ingress spoke. The hub must be configured with ip nhrp redirect to generate these messages when it receives traffic destined for a network reachable via another spoke. The spoke then uses ip nhrp shortcut to install a direct route, but the hub-side command is ip nhrp redirect.

Exam trap

The trap here is confusing the hub-side command ip nhrp redirect with the spoke-side command ip nhrp shortcut, which must be applied on different devices to achieve the same feature.

55
MCQhard

A network architect is designing a FlexVPN solution using IKEv2 between a hub and multiple spokes. The hub must authenticate spokes using certificates, and spokes must authenticate the hub. The architect wants to ensure that the hub can verify the revocation status of spoke certificates in real time. Which mechanism should be implemented?

A.Configure CRL checking on the hub.
B.Configure OCSP on the hub.
C.Enable certificate enrollment using SCEP.
D.Use pre-shared keys with certificate mapping.
AnswerB

OCSP (Online Certificate Status Protocol) allows the hub to query an OCSP responder in real time to check the revocation status of a spoke's certificate during IKEv2 authentication. This meets the real-time requirement. Cisco IOS supports OCSP for IKEv2, enabling immediate revocation checks.

Why this answer

OCSP provides real-time certificate revocation status by allowing the hub to query an OCSP responder during IKEv2 authentication. CRL checking is periodic and may not reflect recent revocations. SCEP is for enrollment, and pre-shared keys are a different authentication method.

Therefore, OCSP is the correct choice for real-time revocation checking.

Exam trap

The trap here is equating CRL with real-time revocation; CRLs are downloaded periodically and can be stale, whereas OCSP queries the responder immediately.

56
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes should be able to communicate directly with each other without traffic traversing the hub. The hub router interface is already configured with 'ip nhrp network-id 1' and 'ip nhrp map multicast dynamic'. Which additional command must be configured on the hub to allow spoke-to-spoke direct tunnels?

A.ip nhrp shortcut
B.ip nhrp network-id 1
C.ip nhrp map multicast dynamic
D.ip nhrp redirect
AnswerD

The 'ip nhrp redirect' command on the hub enables NHRP redirect messages, which inform the originating spoke that a shorter path exists to the destination spoke. This allows the spoke to initiate a direct tunnel, achieving Phase 3 behavior. Without it, spokes continue to route through the hub.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path to another spoke. The spoke then uses 'ip nhrp shortcut' to create a direct tunnel. The hub must have 'ip nhrp redirect' configured to enable this behavior.

The other options are either already configured or belong on the spoke.

Exam trap

The trap here is confusing the hub-side command 'ip nhrp redirect' with the spoke-side command 'ip nhrp shortcut', or assuming that multicast mapping alone enables spoke-to-spoke tunnels.

57
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the transform set. Which command should be used to verify the transform set configured for the crypto map on the local router?

A.show crypto map
B.show crypto ipsec transform-set
C.show crypto isakmp sa
D.show crypto ipsec sa
AnswerA

The show crypto map command displays the crypto map configuration, including the transform set, peer, and ACL. It shows the transform set name configured for each crypto map entry, which is exactly what the engineer needs to verify. This command works regardless of Phase 2 status and is the correct choice for checking configuration.

Why this answer

To verify the transform set configured in a crypto map, the show crypto map command is used. It displays the crypto map entries, including the transform set name, peer, and ACL. This allows the engineer to confirm the local configuration and compare it with the remote peer to identify mismatches.

Exam trap

The trap here is selecting show crypto ipsec sa, which only shows active SAs and would be empty if Phase 2 fails, rather than checking the configuration with show crypto map.

58
MCQmedium

A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?

A.IKEv2 with a hub-and-spoke profile on the key server
B.Group Domain of Interpretation (GDOI)
C.IPsec SA negotiation using ISAKMP aggressive mode
D.NHRP with a next-hop server mapping
AnswerB

GDOI is the protocol the key server uses in GET VPN to distribute the Group Security Association, including the rekey messages carrying updated keys and policies. Group members register with the key server over GDOI, receive the shared keys, and then encrypt traffic directly between themselves without per-pair tunnels. This matches the requirement for identical keys pushed from a single key server.

Why this answer

GET VPN uses the Group Domain of Interpretation so that a key server can distribute a shared Group Security Association and push rekey messages to all group members. Members register with the key server, obtain the same keys and policies, and then encrypt traffic directly with one another over the provider network without building point-to-point tunnels. This preserves the any-to-any model and keeps rekeying centralized on the key server.

Exam trap

The trap here is assuming that any key-distribution need is solved by IKE, when GET VPN specifically relies on GDOI for group key and rekey delivery.

59
MCQmedium

A network engineer is deploying GET VPN across an MPLS L3VPN service provider network. The key server is reachable by all group members, and the engineer wants to avoid rekeying storms when many group members reboot simultaneously after a power outage. Which mechanism should the engineer configure on the key server to spread rekey retransmissions over a period of time?

A.Configure the key server with a rekey retransmit interval and a retransmit limit, and enable the rekey acknowledgment feature so members request unicast retransmissions.
B.Configure the key server with a rekey retransmit interval and disable the rekey acknowledgment, forcing members to pull rekeys at randomized intervals.
C.Configure the group members with a longer registration timeout so they wait longer before contacting the key server after reboot.
D.Configure the key server to use a shorter rekey lifetime so that keys expire quickly and members are forced to re-register frequently.
AnswerA

GET VPN rekey retransmission with acknowledgment lets the key server pace unicast retransmissions to members that did not receive the multicast rekey. When a large number of group members reboot together, the key server sends the multicast rekey, then retransmits at the configured interval to non-responding members, up to the retransmit limit. This prevents an overload of simultaneous unicast rekeys while still guaranteeing key delivery.

Why this answer

The key server in GET VPN distributes the group key via multicast and then uses reliable rekey retransmission with acknowledgment to unicast the rekey to members that did not receive it. Configuring a retransmit interval and retransmit limit spreads those unicast retransmissions over time, so a large number of members rebooting simultaneously do not overload the key server. This preserves key synchronization across the group without disabling the reliability mechanism that guarantees delivery.

Exam trap

The trap here is assuming that disabling rekey acknowledgment reduces load, when in fact acknowledgment is the mechanism that lets the key server retransmit missing rekeys reliably.

60
MCQmedium

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub has a public IP address and is reachable. Spokes are behind NAT devices and have dynamic public IP addresses. Which technology allows spokes to communicate directly without routing traffic through the hub?

A.NHRP redirect
B.NHRP resolution
C.NHRP shortcut
D.NHRP registration
AnswerC

NHRP shortcut allows a spoke to dynamically create a direct tunnel to another spoke when it receives an NHRP redirect from the hub. This enables direct spoke-to-spoke communication, bypassing the hub, which is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, NHRP shortcut enables direct spoke-to-spoke tunnels. When a spoke sends traffic to another spoke via the hub, the hub sends an NHRP redirect, and the spoke then uses NHRP shortcut to establish a direct tunnel.

Exam trap

The trap here is confusing NHRP redirect with NHRP shortcut; redirect is the trigger, but shortcut is the mechanism that actually creates the direct tunnel.

61
MCQmedium

A network engineer is deploying GET VPN with Cisco IOS routers to provide any-to-any encrypted communication over a private MPLS WAN. The design requires that a router joining the group automatically receives the current group security policy from the group controller without any manual pre-shared key configuration on the member. Which protocol should the engineer configure to dynamically distribute the group encryption keys from the key server to the group members?

A.GDOI
B.IKEv2
C.ISAKMP
D.NHRP
AnswerA

GDOI is the group key management protocol used by GET VPN. The key server acts as the group controller/key server, and group members register with it using a group identity and IKE phase 1, then receive the rekey messages containing the IPsec SA policy and TEK/KEK keys. This allows automatic, scalable key distribution without per-member manual pre-shared key configuration, matching the scenario requirement exactly.

Why this answer

GET VPN relies on GDOI for group key management. The key server (group controller/key server) distributes the group security policy and encryption keys to registered group members via rekey messages, enabling scalable any-to-any encryption over a private WAN without point-to-point tunnels. GDOI is the protocol that dynamically distributes the group encryption keys, satisfying the requirement for automatic key delivery without manual pre-shared key configuration on each member.

Exam trap

The trap here is confusing the IKE phase 1 protocol used for registration with the group key management protocol that actually distributes the group encryption keys.

62
MCQhard

A network administrator is deploying a GET VPN using Cisco IOS routers. The key server is configured with a cooperative key server (COOP) for redundancy. The administrator notices that some group members are not registering with the primary key server. Which protocol and port must be allowed through the firewall for the group members to register with the key server?

A.GDOI on UDP port 848
B.ISAKMP on UDP port 500
C.IPsec ESP on IP protocol 50
D.NAT-T on UDP port 4500
AnswerA

GET VPN group members use the GDOI protocol to register with the key server. GDOI operates on UDP port 848. Allowing this port through the firewall is essential for group members to register and receive keys and policies from the key server.

Why this answer

GET VPN group members use GDOI on UDP port 848 to register with the key server. This port must be permitted through firewalls to allow registration and key retrieval.

Exam trap

The trap here is assuming GET VPN uses standard IPsec ports like UDP 500 or 4500 for registration, when it actually uses GDOI on UDP 848.

63
MCQhard

A network administrator is configuring DMVPN Phase 3 with a hub-and-spoke topology. The administrator wants to enable spoke-to-spoke communication directly without traversing the hub. Which command must be configured on the hub router to allow spoke-to-spoke tunnels?

A.ip nhrp network-id 1
B.ip nhrp redirect
C.ip nhrp shortcut
D.ip nhrp map multicast dynamic
AnswerB

The 'ip nhrp redirect' command on the hub enables DMVPN Phase 3 functionality. When a spoke sends traffic to another spoke via the hub, the hub sends an NHRP redirect message to the originating spoke, informing it of a better path directly to the destination spoke. This allows the originating spoke to initiate a direct tunnel to the destination spoke, bypassing the hub for subsequent packets. This is a key component of DMVPN Phase 3.

Why this answer

The correct answer is 'ip nhrp redirect' on the hub. In DMVPN Phase 3, the hub uses NHRP redirect messages to inform spokes about a better direct path to other spokes. When a spoke receives a redirect, it can establish a direct tunnel to the destination spoke, reducing latency and hub load.

This command is essential on the hub to enable this behavior. The spoke routers must also have 'ip nhrp shortcut' configured to act on the redirects.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', and misplacing them on the wrong routers (hub vs. spoke).

64
MCQmedium

A network engineer is deploying a GET VPN solution across an MPLS VPN WAN. The group members must encrypt traffic between any pair of sites without establishing point-to-point tunnels, and the key server must distribute a common encryption policy to all members. The engineer has configured the key server with a rekey policy but group members are not receiving rekeys. Which action must be taken on the key server to enable successful rekey transmission?

A.Change the key server to use a different group identity (GDOI group ID) that matches the members.
B.Configure the group members with the rekey retransmit timer set to a lower value.
C.Configure the key server to use IKEv2 for rekey authentication instead of IKEv1.
D.Enable unicast rekey on the key server so that rekeys are sent directly to each group member.
AnswerD

By default, GET VPN key servers send rekeys via multicast to the group address. If the underlay network does not support multicast or the group members are not receiving multicast rekeys, enabling unicast rekey ensures each member receives the rekey directly. This is a common requirement in MPLS VPN or non-multicast-capable transport networks.

Why this answer

GET VPN key servers typically send rekeys using multicast to the group address. In networks that do not support multicast or where multicast is not enabled on the transport, group members will not receive rekeys. Enabling unicast rekey on the key server forces rekeys to be sent directly to each registered group member's unicast address, ensuring they receive the updated policy.

This is a standard configuration adjustment for non-multicast underlays.

Exam trap

The trap here is assuming that rekey delivery is always multicast and that multicast is available on all transport networks, when in fact unicast rekey may be required for non-multicast-capable underlays.

65
MCQeasy

Which protocol should be used to dynamically distribute encryption keys for a GET VPN deployment?

A.GDOI
B.IKEv2
C.ISAKMP
D.IPsec
AnswerA

GDOI (Group Domain of Interpretation) is the protocol used in GET VPN to distribute group keys and policies from the key server to group members. It enables the key server to push encryption keys, rekey messages, and ACL policies to all group members, facilitating secure any-to-any communication without point-to-point tunnels.

Why this answer

GET VPN uses the Group Domain of Interpretation (GDOI) protocol for group key management. The key server uses GDOI to distribute encryption keys, rekey messages, and security policies to all group members. This allows members to encrypt traffic to each other without establishing point-to-point tunnels, preserving the any-to-any nature of the underlying network.

Exam trap

The trap here is confusing GDOI with IKE; while IKE is used for point-to-point VPNs, GDOI is specifically designed for group key distribution in GET VPN.

66
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?

A.Enable NHRP shortcut on the hub tunnel interface.
B.Set the tunnel interface to multipoint GRE on all spokes.
C.Enable NHRP redirect on the hub tunnel interface.
D.Configure a unique NHRP network ID on each spoke.
AnswerC

NHRP redirect is a Phase 3 feature that allows the hub to inform spokes of a better path to another spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the originating spoke, which then resolves the destination NBMA address and builds a direct tunnel. Without NHRP redirect, spokes continue to route through the hub, defeating the purpose of Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel. Configuring NHRP redirect on the hub is essential to enable spoke-to-spoke communication without traversing the hub for every packet.

Exam trap

The trap here is confusing where NHRP redirect and NHRP shortcut are configured: redirect goes on the hub, shortcut on the spokes.

67
MCQeasy

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS XE routers. The administrator wants to ensure that the VPN tunnel only encrypts traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet. Which configuration element defines the traffic to be encrypted?

A.transform set
B.ISAKMP policy
C.crypto ACL
D.crypto map
AnswerC

The crypto ACL (extended access list) defines which traffic is interesting and should be protected by the IPsec VPN. In this scenario, an ACL permitting traffic from 10.1.1.0/24 to 10.2.2.0/24 and vice versa would be referenced by the crypto map. This ACL is the element that specifies the traffic to be encrypted.

Why this answer

In a site-to-site IPsec VPN, the crypto ACL (an extended access list) is used to define interesting traffic that should be encrypted and sent through the tunnel. The crypto map references this ACL to match packets. The transform set and ISAKMP policy define how to protect the traffic and negotiate the tunnel, but they do not select the traffic.

Exam trap

The trap here is confusing the role of the crypto ACL with the crypto map or transform set, which are used to apply protection but do not define the traffic itself.

68
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The tunnel is up, but traffic is not passing. The administrator runs show crypto ipsec sa and notices that the inbound and outbound ESP SAs are present, but the packet counters are not incrementing. The ACL used for the crypto map is permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. Which action is most likely to resolve the issue?

A.Confirm that the transform set matches on both peers.
B.Ensure that the preshared key is identical on both peers.
C.Check the routing table to ensure that the remote protected subnet is reachable via the tunnel interface or that the next hop is correct.
D.Verify that the crypto ACL on the remote peer is a mirror image of the local ACL.
AnswerC

If the IPsec SAs are established but packet counters are not incrementing, the router is not forwarding interesting traffic into the tunnel. This often occurs when the route to the remote protected subnet points out of the physical interface instead of the tunnel interface, or when there is no route at all. Correcting the routing ensures that packets matching the crypto ACL are sent through the VPN.

Why this answer

When IPsec SAs are up but packet counters remain at zero, the router is not identifying or routing traffic into the VPN. The most common cause is a routing issue: the remote subnet is not reachable via the tunnel, or a more specific route directs traffic elsewhere. Verifying the routing table and ensuring the tunnel interface is the next hop for the protected subnet resolves the problem.

Exam trap

The trap here is assuming that an ACL mismatch is the culprit because it's a common VPN issue, but with SAs established, the problem is more likely routing or interesting traffic not being matched.

69
MCQmedium

A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?

A.IPsec must be configured in transport mode to preserve the original IP header.
B.The tunnel interface must be configured with the tunnel mode gre multipoint command.
C.The crypto ACL must permit GRE (protocol 47) traffic.
D.The crypto ACL must permit OSPF (protocol 89) traffic.
AnswerC

For GRE over IPsec, the crypto ACL defines which traffic is encrypted. Since GRE encapsulates the multicast traffic, the outer IP packet uses IP protocol 47. Therefore, the crypto ACL must permit GRE traffic between the tunnel endpoints. This ensures that all GRE-encapsulated packets, including multicast, are encrypted by IPsec.

Why this answer

In a GRE over IPsec configuration, GRE encapsulates the multicast traffic, and then IPsec encrypts the GRE packets. The crypto ACL must match the GRE protocol (IP protocol 47) between the tunnel source and destination. This allows multicast and broadcast traffic to be carried over the tunnel because GRE handles the multicast encapsulation, and IPsec provides encryption.

Exam trap

The trap here is thinking that the crypto ACL should match the multicast or routing protocol directly, rather than the GRE encapsulation that carries them.

70
Multi-Selectmedium

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP, and wants spokes to reach other spokes directly without routing through the hub for every packet. The engineer must configure the hub so that it advertises a default route to the spokes while still allowing spoke-to-spoke shortcut tunnels. (Choose two.)

Select 2 answers
A.Disable split horizon on the hub's mGRE interface to allow spoke routes to be re-advertised.
B.Enable NHRP redirect on the hub so it can inform spokes of a better path to the destination.
C.Configure the hub with a default route pointing to the provider and redistribute it into the routing protocol with a metric that spokes accept.
D.Configure the spokes with a static route for every remote spoke subnet pointing at the hub.
E.Configure NHRP shortcut on each spoke to allow it to install and use a direct route learned from the redirect.
AnswersB, E

NHRP redirect is a Phase 3 feature that lets the hub inspect traffic arriving on its mGRE interface and send a redirect message to the originating spoke when a shorter path exists. The spoke then resolves the destination NBMA address and builds a direct tunnel to the target spoke. Without redirect, spokes keep sending all inter-spoke traffic through the hub, so this is required for shortcut behavior.

Why this answer

DMVPN Phase 3 achieves spoke-to-spoke shortcuts through two cooperating NHRP features. The hub enables NHRP redirect so it can tell a spoke that a better path exists, and each spoke enables NHRP shortcut so it can resolve the destination and install a temporary direct route. Together these allow direct tunnels while the hub still advertises a summarizable default route to all spokes.

Exam trap

The trap here is thinking that distributing a default route or adjusting split horizon enables shortcuts, when Phase 3 specifically depends on NHRP redirect on the hub and NHRP shortcut on the spokes.

71
Multi-Selecthard

A network engineer is implementing a DMVPN Phase 3 network with NHRP and mGRE on the hub. The design requires that spoke-to-spoke traffic be able to bypass the hub after resolution, and that the hub not be required to advertise specific routes to the spokes. Which two configuration elements are required to achieve shortcut switching and default-route-only behavior on the spokes? (Choose two.)

Select 2 answers
A.Disable NHRP shortcut on the spokes so they always forward through the hub first.
B.Configure the hub to summarize or advertise a default route to the spokes, and configure the spokes to use the hub as their default gateway.
C.Enable NHRP redirect on the hub so it can inform spokes when a better path to the destination exists.
D.Configure the spokes with a static NHRP map for every other spoke in the topology.
E.Configure the hub with a route map that tags the default route so spokes prefer the hub path over shortcuts.
AnswersB, C

Phase 3 shortcut switching relies on the spokes having a default route pointing to the hub so they forward all unknown traffic to the hub initially. The hub advertises a default route rather than specific prefixes, which keeps the spoke routing tables small. When a spoke needs to reach another spoke, NHRP resolves the destination and installs a shortcut route, allowing traffic to bypass the hub while the default route remains for everything else.

Why this answer

DMVPN Phase 3 combines a hub-advertised default route with NHRP redirect and shortcut switching. The spokes point their default route at the hub, so unknown destinations initially go through the hub. When the hub sees traffic that could take a better path, NHRP redirect tells the source spoke to resolve the destination, and NHRP shortcut installs a direct route.

This yields small spoke routing tables plus optimized spoke-to-spoke paths.

Exam trap

The trap here is thinking Phase 3 shortcut switching works without NHRP redirect, when redirect is what prompts the spoke to resolve a direct path.

72
Multi-Selectmedium

A network engineer is configuring a DMVPN Phase 3 network with mGRE and NHRP. The hub router must be able to dynamically learn spoke routes and advertise them to other spokes. Which two statements are true regarding the configuration of the hub to support spoke-to-spoke communication in DMVPN Phase 3? (Choose two.)

Select 2 answers
A.The hub must have 'ip nhrp shortcut' configured on its tunnel interface.
B.The hub must have a route to all spoke networks, either through a routing protocol or summary route.
C.The hub must have 'ip nhrp redirect' configured on its tunnel interface.
D.The hub must have 'ip nhrp network-id' configured with the same value as the spokes.
E.The hub must have 'ip nhrp map multicast dynamic' configured to support multicast traffic.
AnswersB, C

In DMVPN Phase 3, the hub still needs to know how to reach all spoke networks to provide initial connectivity and to forward traffic when a direct tunnel is not yet established. This is typically achieved by running a routing protocol on the hub and spokes, or by configuring a summary route on the hub. Without this, the hub cannot route traffic to the correct spoke, and spoke-to-spoke communication may fail.

Why this answer

In DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to inform spokes of a better direct path, and it must have a route to all spoke networks to provide initial connectivity and forwarding. The spokes require 'ip nhrp shortcut' to act on redirects. The other options are either not specific to Phase 3 or are configured on spokes.

Exam trap

The trap here is confusing where 'ip nhrp shortcut' is configured; it belongs on the spokes, not the hub, and is essential for them to use the redirect messages.

73
MCQhard

A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?

A.Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key
B.Configure a local AAA authorization list on the IKEv2 profile to authorize the spoke's group policy
C.Bind the IKEv2 profile to a virtual template interface used for the spoke's virtual access interface
D.Enable RSA signature authentication on the IKEv2 profile so the hub can validate the spoke without a keyring
AnswerA

IKEv2 pre-shared key authentication on Cisco IOS requires the hub to match the peer's identity against an entry in the IKEv2 keyring, where the pre-shared key is defined per peer or per subnet. Without a matching keyring peer entry, the hub cannot retrieve the pre-shared key during IKE_AUTH even though the profile exists, and the exchange fails. Adding the spoke identity with the correct key resolves the failure.

Why this answer

Cisco IOS IKEv2 pre-shared key authentication relies on the IKEv2 keyring to look up the key associated with the peer's identity. The IKEv2 profile references the keyring, but the key itself must exist in a peer or subnet entry that matches the spoke. Because no AAA authentication is configured, the keyring is the only source of the key, so adding the spoke identity with the matching key fixes the IKE_AUTH failure.

Exam trap

The trap here is believing that configuring the same pre-shared key under the IKEv2 profile is sufficient, when the key must be defined in an IKEv2 keyring entry that matches the peer's identity.

74
MCQeasy

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 network to the 10.2.2.0/24 network is encrypted. Which type of ACL must be used in the crypto map to define the interesting traffic?

A.A standard ACL that permits the 10.1.1.0/24 network.
B.An extended ACL that denies IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
C.An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
D.A named ACL that permits all IP traffic.
AnswerC

For IPsec site-to-site VPNs, the crypto map ACL must be an extended ACL that defines the interesting traffic. It should permit IP traffic from the local subnet to the remote subnet. This ACL is used to match packets that need encryption. A standard ACL cannot specify destination addresses or protocols, so it is insufficient.

Why this answer

In Cisco IPsec configuration, the crypto map references an extended ACL to identify interesting traffic. The ACL must permit IP traffic from the local subnet to the remote subnet. This ensures that only packets matching those criteria are encrypted and sent through the VPN tunnel.

Standard ACLs or overly broad ACLs are incorrect.

Exam trap

The trap here is using a standard ACL or a deny statement, misunderstanding that the crypto ACL must be an extended ACL that permits the specific traffic.

75
MCQeasy

A network administrator is setting up a site-to-site VPN between two Cisco IOS routers and wants to use IKEv2 with certificate-based authentication. The administrator has already installed the identity certificate and the CA certificate on both routers. Which additional configuration is required on each router so that IKEv2 can validate the peer's certificate during the IKE_AUTH exchange?

A.Configure a pre-shared key on both routers as a fallback in case certificate validation fails.
B.Configure the IKEv2 profile with the authentication local rsa-sig command only, without referencing a trustpoint.
C.Reference the PKI trustpoint in the IKEv2 profile using the pki trustpoint command so the router knows which CA to use for validation.
D.Enable the crypto pki server on both routers so each can issue certificates to the other.
AnswerC

For certificate authentication in IKEv2, the router must know which trustpoint to use for its own certificate and for validating the peer certificate chain. Referencing the trustpoint in the IKEv2 profile with the pki trustpoint command supplies that binding. Without it, the router cannot select the correct CA chain or send the proper certificate during IKE_AUTH, so the negotiation fails even though certificates are installed.

Why this answer

IKEv2 certificate authentication requires the router to select a trustpoint that identifies its own certificate and the CA chain used to validate the peer. The pki trustpoint command under the IKEv2 profile provides that binding. With the trustpoint referenced, the router can present its identity certificate and verify the peer's certificate during IKE_AUTH, completing authentication even though the certificates were already installed.

Exam trap

The trap here is believing that installing certificates is sufficient, when IKEv2 also needs an explicit trustpoint reference in the profile to know which CA chain to use.

Page 1 of 2 · 79 questions totalNext →

Ready to test yourself?

Try a timed practice session using only VPN Technologies questions.