350-401 Security Practice Question
A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?
⚠ Common exam trap
The trap here is equating remote access VPN with SSL VPN only, overlooking that FlexVPN also supports remote access with IKEv2 and per-user policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FlexVPN with IKEv2 and per-user attributes.
FlexVPN is the correct choice because it is built on IKEv2 and supports IPv6 transport. It also provides per-user policy enforcement through authorization attributes, making it ideal for a remote access VPN headend. Other options either do not support IKEv2, are designed for site-to-site topologies, or lack per-user policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dynamic Multipoint VPN (DMVPN) with mGRE and NHRP.
Why it's wrong here
DMVPN is designed for site-to-site hub-and-spoke or spoke-to-spoke topologies, not for remote user access. It uses mGRE and NHRP to build tunnels on demand. While it supports IKEv2 and IPv6, it does not provide per-user policy enforcement for individual remote users connecting from various locations.
- ✓
FlexVPN with IKEv2 and per-user attributes.
Why this is correct
FlexVPN is a Cisco IOS framework that uses IKEv2 and supports IPv6 transport. It allows per-user policy enforcement through authorization attributes such as IP address, DNS, and split tunnel ACLs. It is well suited for remote access VPN headends and can scale to many users while maintaining granular policy control.
- ✗
GET VPN with Group Domain of Interpretation (GDOI).
Why it's wrong here
GET VPN is designed for group encryption over a private WAN, typically for site-to-site traffic. It uses GDOI for key management and does not provide per-user policy enforcement. It also assumes a trusted transport and is not intended for remote user access over the Internet.
- ✗
SSL VPN with Cisco AnyConnect.
Why it's wrong here
SSL VPN uses TLS and is excellent for remote access, but it does not use IKEv2. The requirement explicitly asks for IKEv2 support. While SSL VPN can provide per-user policy enforcement, it fails the IKEv2 criterion and is therefore not the correct choice for this scenario.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.