hardMultiple SelectObjective-mapped
300-410 Practice Question: Which TWO statements correctly describe the use…
Which TWO statements correctly describe the use of IKEv2 for IPsec site-to-site VPNs? (Choose TWO.)
⚠ Common exam trap
Cisco often tests the misconception that IKEv2 uses aggressive mode (like IKEv1) or that its default SA lifetime is 3600 seconds, when in fact IKEv2 uses a simpler exchange and a 24-hour default lifetime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IKEv2 uses UDP port 500 and 4500 for NAT traversal.
IKEv2 uses UDP port 500 for initial IKE SA establishment and port 4500 for NAT traversal (encapsulating IPsec packets in UDP to pass through NAT devices). This is a standard behavior defined in RFC 7296, ensuring compatibility with NAT environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IKEv2 uses UDP port 500 and 4500 for NAT traversal.
Why this is correct
Correct. IKEv2 uses UDP 500 for initial exchanges and UDP 4500 when NAT is detected.
- ✗
IKEv2 supports only pre-shared keys for authentication.
Why it's wrong here
Incorrect. IKEv2 supports pre-shared keys, digital certificates, and EAP.
- ✗
IKEv2 uses aggressive mode to establish the IKE SA.
Why it's wrong here
Incorrect. Aggressive mode is a feature of IKEv1; IKEv2 uses a different exchange mechanism.
- ✓
IKEv2 can authenticate using EAP (Extensible Authentication Protocol).
Why this is correct
Correct. IKEv2 supports EAP, which allows integration with authentication servers like RADIUS.
- ✗
The default IKEv2 SA lifetime is 3600 seconds.
Why it's wrong here
Incorrect. The default IKEv2 SA lifetime is 86400 seconds (24 hours).
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.