Courseiva
Security →easyMultiple Choice

350-401 Security Practice Question

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?

⚠ Common exam trap

The trap here is equating remote access VPN with SSL VPN only, overlooking that FlexVPN also supports remote access with IKEv2 and per-user policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FlexVPN with IKEv2 and per-user attributes.

FlexVPN is the correct choice because it is built on IKEv2 and supports IPv6 transport. It also provides per-user policy enforcement through authorization attributes, making it ideal for a remote access VPN headend. Other options either do not support IKEv2, are designed for site-to-site topologies, or lack per-user policy enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic Multipoint VPN (DMVPN) with mGRE and NHRP.

    Why it's wrong here

    DMVPN is designed for site-to-site hub-and-spoke or spoke-to-spoke topologies, not for remote user access. It uses mGRE and NHRP to build tunnels on demand. While it supports IKEv2 and IPv6, it does not provide per-user policy enforcement for individual remote users connecting from various locations.

  • ✓

    FlexVPN with IKEv2 and per-user attributes.

    Why this is correct

    FlexVPN is a Cisco IOS framework that uses IKEv2 and supports IPv6 transport. It allows per-user policy enforcement through authorization attributes such as IP address, DNS, and split tunnel ACLs. It is well suited for remote access VPN headends and can scale to many users while maintaining granular policy control.

  • ✗

    GET VPN with Group Domain of Interpretation (GDOI).

    Why it's wrong here

    GET VPN is designed for group encryption over a private WAN, typically for site-to-site traffic. It uses GDOI for key management and does not provide per-user policy enforcement. It also assumes a trusted transport and is not intended for remote user access over the Internet.

  • ✗

    SSL VPN with Cisco AnyConnect.

    Why it's wrong here

    SSL VPN uses TLS and is excellent for remote access, but it does not use IKEv2. The requirement explicitly asks for IKEv2 support. While SSL VPN can provide per-user policy enforcement, it fails the IKEv2 criterion and is therefore not the correct choice for this scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.