Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network administrator is configuring a Cisco IOS XE router to act as a VPN headend with IKEv2. The security policy requires that the router authenticate to peers using a certificate from a corporate PKI, and that peers authenticate using EAP-MSCHAPv2. Which IKEv2 authentication configuration on the headend meets these requirements?

⚠ Common exam trap

The trap here is mixing up local and remote authentication keywords, or assuming that RSA signatures on both sides would satisfy an EAP requirement for peers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'authentication local rsa-sig' and 'authentication remote eap query-identity' under the IKEv2 profile.

IKEv2 profiles separate local and remote authentication methods. To use a certificate for the headend, 'authentication local rsa-sig' is required. To authenticate peers with EAP-MSCHAPv2, 'authentication remote eap query-identity' is used, which triggers EAP negotiation and allows the peer to respond with EAP-MSCHAPv2 credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure 'authentication local rsa-sig' and 'authentication remote eap query-identity' under the IKEv2 profile.

    Why this is correct

    The 'authentication local rsa-sig' command specifies that the local router uses RSA signatures, which are derived from a certificate, for its own authentication. The 'authentication remote eap query-identity' command instructs the router to request the peer's identity and use EAP for remote authentication, which supports EAP-MSCHAPv2. This combination matches the policy requirements for certificate-based local auth and EAP-based remote auth.

  • ✗

    Configure 'authentication local pre-share' and 'authentication remote pre-share' under the IKEv2 profile.

    Why it's wrong here

    Pre-shared key authentication does not use certificates or EAP. This configuration would require both sides to use a shared secret, which violates the requirement for certificate-based local authentication and EAP-MSCHAPv2 for peers. It is a simpler method but does not meet the stated security policy.

  • ✗

    Configure 'authentication local eap query-identity' and 'authentication remote rsa-sig' under the IKEv2 profile.

    Why it's wrong here

    This reverses the roles: it would make the headend authenticate using EAP and expect the peer to use RSA signatures. The requirement is the opposite—headend uses a certificate, peers use EAP-MSCHAPv2. This configuration would fail to meet the policy and likely cause authentication failures because the peer would not present a certificate.

  • ✗

    Configure 'authentication local rsa-sig' and 'authentication remote rsa-sig' under the IKEv2 profile.

    Why it's wrong here

    Using RSA signatures for both local and remote authentication means both sides must have certificates. This does not accommodate EAP-MSCHAPv2 for peer authentication. While it would provide certificate-based mutual authentication, it does not satisfy the requirement for EAP-based remote authentication, which is often used for remote access VPN clients.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.