Courseiva

300-410 · topic practice

VPN Technologies practice questions

VPN Technologies covers IPsec site-to-site and remote-access tunnels, DMVPN, FlexVPN, GET VPN, and IKEv1/IKEv2 negotiation on Cisco IOS and IOS XE routers. Questions are scenario-based: you pick protocols, match crypto map or profile parameters on both peers, read debug and show crypto output, and diagnose Phase 1 versus Phase 2 failures.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: VPN Technologies

What the exam tests

What to know about VPN Technologies

Be able to configure and verify IPsec, DMVPN, FlexVPN, and GET VPN on Cisco routers, and to isolate whether a tunnel failure is Phase 1 or Phase 2. The most important thing: confirm both peers agree on every IKE and IPsec parameter, including identity and proxy ACLs.

IKEv1/IKEv2 Phase 1 and Phase 2 parameter matching: encryption, hashing, DH group, lifetime, and pre-shared key or certificate authentication

IPsec crypto map, IPsec profile, and transform set configuration, including ACL or VTI-based interesting traffic selection

DMVPN Phase 1/2/3 with NHRP, mGRE, and tunnel protection, plus FlexVPN hub-and-spoke IKEv2 authorization

GET VPN group member and key server roles, including key distribution and the GDOI protocol

Watch out for

Common VPN Technologies exam traps

  • ▸Mismatched Phase 2 transform sets, proxy ACLs, or PFS settings between peers, which lets Phase 1 complete but makes Phase 2 fail with QM FSM errors.
  • ▸Assuming a single IKEv2 or IPsec profile can serve all spokes without matching authentication, authorization, or local/remote identity settings per peer.
  • ▸Confusing GET VPN key distribution with IKE: GDOI uses the key server, not standard IPsec IKE, to push encryption keys to group members.

Practice set

VPN Technologies questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Review the full OSPF breakdown →

A network engineer is configuring a GRE tunnel between two Cisco IOS routers, R1 and R2, to carry OSPF traffic over an ISP network. The tunnel source on R1 is GigabitEthernet0/0 (IP 203.0.113.1), and the tunnel destination is R2's GigabitEthernet0/0 (IP 203.0.113.2). The engineer enters the following commands on R1:

interface Tunnel0
 ip address 10.0.0.1 255.255.255.252

tunnel source GigabitEthernet0/0 tunnel destination 203.0.113.2 tunnel mode gre ip

After configuration, the tunnel interface is up/up, but OSPF adjacency does not form. What is the most likely cause?

Question 2mediummultiple choice
Read the full VPN explanation →

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The hub router is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. After configuration, spoke-to-spoke traffic still goes through the hub. Which action resolves this issue?

Question 3mediummultiple choice
Read the full MPLS explanation →

A network engineer is configuring a VRF-lite based MPLS VPN on a Cisco IOS router. The router has two VRFs: CUSTOMER_A and CUSTOMER_B. The engineer wants to ensure that traffic from CUSTOMER_A can reach the global routing table for management purposes, but CUSTOMER_B should remain isolated. Which configuration accomplishes this?

Question 4hardmultiple choice
Read the full VPN explanation →

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN). The company requires that all routers in the group use the same encryption keys and that key distribution be handled by a central server. Which component is responsible for distributing the group security policy and keys to the group members?

Question 5hardmultiple choice
Study the full EIGRP explanation →

A company uses DMVPN Phase 2 with EIGRP as the routing protocol. The hub is configured with a single mGRE tunnel interface. Spokes are configured with ip nhrp map multicast dynamic and ip nhrp registration no-unique. The network engineer notices that spoke-to-spoke tunnels are not forming even though the hub is reachable. Which configuration change on the spokes is required to enable spoke-to-spoke tunnels in Phase 2?

Question 6hardmulti select
Read the full VPN explanation →

A network engineer is deploying DMVPN Phase 2 with IPsec protection. The hub is configured with a point-to-multipoint GRE interface and NHRP. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spokes can dynamically establish direct tunnels. Which two configurations are required on the spokes to achieve this? (Choose two.)

Question 7mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a VRF-aware IPsec tunnel on a Cisco IOS router. The router has two VRFs: VRF-A and VRF-B. The engineer wants traffic from VRF-A to be encrypted and sent over a tunnel to a remote peer, while VRF-B traffic should remain unencrypted and use a different path. Which configuration step is required to map the IPsec tunnel to VRF-A?

Question 8mediummultiple choice
Read the full VPN explanation →

A network administrator is configuring a VRF-aware IPSec VPN on a Cisco IOS router. The router must support overlapping IP addresses for two different customers. The administrator has created VRF CUST-A and VRF CUST-B. Which configuration is required to enable IPSec to operate within a VRF?

Question 9mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP on Cisco IOS routers. The hub router is configured with `ip nhrp map multicast dynamic` and `ip nhrp network-id 100`. Spoke routers register successfully, and the hub can ping all spoke tunnel IPs. However, when a spoke tries to reach another spoke's LAN subnet, the packet is dropped at the hub. Which configuration on the hub is most likely missing to allow spoke-to-spoke traffic?

Question 10hardmulti select
Read the full VPN explanation →

A network administrator is troubleshooting a DMVPN Phase 3 configuration on a Cisco IOS router. The hub router is configured with `ip nhrp redirect`, and spoke routers are configured with `ip nhrp shortcut`. However, spoke-to-spoke communication is failing; packets are being dropped or taking a suboptimal path through the hub. Which two actions should the administrator take to resolve the issue? (Choose two.)

Question 11hardmulti select
Study the full EIGRP explanation →

A network engineer is implementing DMVPN Phase 2 with EIGRP as the routing protocol. To ensure proper spoke-to-spoke communication, the engineer must configure the hub and spokes correctly. Which two statements about DMVPN Phase 2 with EIGRP are true? (Choose two.)

Question 12hardmultiple choice
Read the full VPN explanation →

A network administrator is troubleshooting a DMVPN Phase 2 network where spoke-to-spoke communication fails. The hub is a Cisco IOS router, and spokes are configured with NHRP. The administrator notices that the hub has a route to the spokes' tunnel networks, but spokes do not have routes to each other's tunnel networks. Which configuration change on the hub is required to allow spokes to dynamically learn routes to other spokes?

Question 13hardmulti select
Read the full VPN explanation →

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers that uses IKEv2. Phase 1 is up, but Phase 2 fails to establish. The administrator suspects a mismatch in the IPsec proposal parameters. Which two parameters must match on both peers for the IPsec SA to be established? (Choose two.)

Question 14mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE on the hub and a single physical interface on each spoke. The engineer wants spokes to communicate directly with each other without traffic transiting the hub, and requires that spoke-to-spoke tunnels are dynamically created only when needed. Which NHRP configuration on the hub is required to support this requirement?

Question 15hardmulti select
Open the full BGP breakdown →

A network engineer is troubleshooting an MPLS Layer 3 VPN. The service provider uses MP-BGP with VPNv4 address family. The engineer notices that the PE router is not receiving routes from a remote PE for a particular VRF. Which two statements are true regarding the operation of MP-BGP in this environment? (Choose two.)

Question 16hardmulti select
Read the full VPN explanation →

A network administrator is deploying a GET VPN solution using Cisco Group Encrypted Transport VPN. The administrator wants to ensure that the key server (KS) and group members (GMs) can successfully establish security associations. Which two statements about GET VPN are true? (Choose two.)

Question 17easymultiple choice
Read the full VPN explanation →

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to carry multicast traffic. The tunnel interface is up, but multicast packets are not being forwarded. The engineer suspects that the tunnel interface needs to be enabled for multicast routing. Which command is required on the tunnel interface to allow multicast traffic to be forwarded?

Question 18mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a VRF-aware IPsec VPN on a Cisco IOS router. The router has two VRFs: VRF-A and VRF-B. The engineer wants to encrypt traffic from VRF-A to a remote site using IPsec. Which additional configuration is required on the crypto map to support VRF-aware IPsec?

Question 19hardmultiple choice
Study the full ACL explanation →

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) with GDOI. The key server (KS) and group members (GMs) are configured. Phase 1 and Phase 2 of GDOI are operational, and the KS has successfully pushed the policy to all GMs. However, traffic between two GMs on the same group is being dropped. The administrator verifies that the ACLs on both GMs match and that no firewall is blocking IPsec. Which action should be taken to resolve the issue?

Question 20mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a VRF-aware IPsec VPN on a Cisco IOS router. The router must support multiple customers, each with overlapping IP address spaces, and each customer's traffic must be encrypted separately. Which IPsec configuration element allows the router to select the correct crypto map for each VRF?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused VPN Technologies sessions

Start a VPN Technologies only practice session

Every question in these sessions is drawn from the VPN Technologies domain — nothing else.

Related practice questions

Related 300-410 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 300-410 exam test about VPN Technologies?
Be able to configure and verify IPsec, DMVPN, FlexVPN, and GET VPN on Cisco routers, and to isolate whether a tunnel failure is Phase 1 or Phase 2. The most important thing: confirm both peers agree on every IKE and IPsec parameter, including identity and proxy ACLs.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just VPN Technologies questions in a focused session?
Yes — the session launcher on this page draws every question from the VPN Technologies domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 300-410 topics?
Use the topic links above to move to related areas, or go back to the 300-410 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 300-410 exam covers. They are not copied from any real exam or dump site.