Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot an…

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue:

R1# show ip route 192.168.2.0

Routing entry for 192.168.2.0/24 Known via "eigrp 100", distance 90, metric 2684416, type internal Redistributing via eigrp 100 Last update from 10.0.0.2 on Tunnel0, 00:00:23 ago Routing Descriptor Blocks:

* 10.0.0.2, from 10.0.0.2, via Tunnel0

Route metric is 2684416, traffic share count is 1 Total delay is 20000 microseconds, minimum bandwidth is 100000 Kbit Reliability 255/255, minimum MTU 1500 bytes Loading 1/255, Hops 1

What does this output indicate?

⚠ Common exam trap

Cisco often tests the misconception that a route learned via a tunnel interface implies the tunnel is down or that dynamic routing is not functioning, but the presence of a recent update and valid next hop confirms the tunnel is operational.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPsec tunnel is up and EIGRP is exchanging routes over the tunnel.

The output shows a route to 192.168.2.0/24 learned via EIGRP (distance 90) with the next hop 10.0.0.2 reachable through Tunnel0. The last update was 23 seconds ago, confirming the tunnel is up and EIGRP is actively exchanging routing information over the IPsec tunnel. This indicates the IPsec Site-to-Site VPN is functioning and dynamic routing is working correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The route to the remote LAN is not present, indicating a routing issue.

    Why it's wrong here

    The output explicitly shows 192.168.2.0/24 present via EIGRP 100 through Tunnel0, so no missing route exists. Engineers suspect routing when a VPN fails, making this tempting. This command is used to confirm a prefix is learned; here it already is.

  • ✓

    The IPsec tunnel is up and EIGRP is exchanging routes over the tunnel.

    Why this is correct

    The route to 192.168.2.0/24 is learned via EIGRP 100 through Tunnel0, with a valid next hop of 10.0.0.2 and a recent update timestamp. This confirms the IPsec tunnel is passing traffic and EIGRP adjacencies are exchanging routes across it.

  • ✗

    The route is using a static route, not a dynamic routing protocol.

    Why it's wrong here

    'Known via eigrp 100' with distance 90 and 'Redistributing via eigrp 100' proves the prefix arrived dynamically, not statically. Static routes appear as 'Known via static' with distance 1. Checking route source is useful when verifying redistribution, but this output already names EIGRP.

  • ✗

    The tunnel interface is down, causing the route to be unreachable.

    Why it's wrong here

    The route is installed and reachable via Tunnel0, with a recent 23-second update from 10.0.0.2, so the tunnel is up. A down tunnel would remove the route from the table. Verifying interface state matters when troubleshooting VPNs, but this output contradicts that conclusion.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.