Courseiva
hardMultiple SelectObjective-mapped

300-410 Practice Question: Which TWO statements correctly describe the use…

Which TWO statements correctly describe the use of IKEv2 for IPsec site-to-site VPNs? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the misconception that IKEv2 uses aggressive mode (like IKEv1) or that its default SA lifetime is 3600 seconds, when in fact IKEv2 uses a simpler exchange and a 24-hour default lifetime.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IKEv2 uses UDP port 500 and 4500 for NAT traversal.

IKEv2 uses UDP port 500 for initial IKE SA establishment and port 4500 for NAT traversal (encapsulating IPsec packets in UDP to pass through NAT devices). This is a standard behavior defined in RFC 7296, ensuring compatibility with NAT environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IKEv2 uses UDP port 500 and 4500 for NAT traversal.

    Why this is correct

    Correct. IKEv2 uses UDP 500 for initial exchanges and UDP 4500 when NAT is detected.

  • IKEv2 supports only pre-shared keys for authentication.

    Why it's wrong here

    Incorrect. IKEv2 supports pre-shared keys, digital certificates, and EAP.

  • IKEv2 uses aggressive mode to establish the IKE SA.

    Why it's wrong here

    Incorrect. Aggressive mode is a feature of IKEv1; IKEv2 uses a different exchange mechanism.

  • IKEv2 can authenticate using EAP (Extensible Authentication Protocol).

    Why this is correct

    Correct. IKEv2 supports EAP, which allows integration with authentication servers like RADIUS.

  • The default IKEv2 SA lifetime is 3600 seconds.

    Why it's wrong here

    Incorrect. The default IKEv2 SA lifetime is 86400 seconds (24 hours).

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.