Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The requirement is that the VPN must support dynamic routing protocol updates across the tunnel and allow multicast traffic between the sites. Which IPsec configuration mode should be used?

⚠ Common exam trap

The trap here is assuming plain IPsec tunnel mode carries multicast and routing protocols, which it does not without GRE or another encapsulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GRE over IPsec using a tunnel interface protected by IPsec

GRE over IPsec creates a virtual tunnel interface that supports multicast and broadcast, enabling dynamic routing protocols to run across the VPN. IPsec then protects the GRE-encapsulated packets. This design satisfies both the routing update and multicast requirements that standard IPsec tunnel mode with a crypto map cannot deliver.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec tunnel mode with a crypto map applied to the physical interface

    Why it's wrong here

    Standard tunnel-mode IPsec with a crypto map can carry unicast traffic between the sites, but it does not natively support multicast or dynamic routing protocols without additional mechanisms. A plain crypto map does not present a routable tunnel interface for multicast, so routing protocol adjacencies and multicast traffic would not flow as required.

  • ✓

    GRE over IPsec using a tunnel interface protected by IPsec

    Why this is correct

    A GRE tunnel interface can carry unicast, multicast, and broadcast traffic, which allows dynamic routing protocols such as OSPF or EIGRP to form adjacencies and exchange updates. Wrapping the GRE tunnel in IPsec protects the traffic. This combination meets both the routing and multicast requirements that plain IPsec tunnel mode cannot satisfy.

  • ✗

    IPsec transport mode with an access list matching only protocol 47

    Why it's wrong here

    Transport mode protects only the payload of the original IP packet and is typically used for host-to-host or with GRE. Matching only GRE protocol 47 without the tunnel interface does not provide the multicast and routing support requested, and transport mode alone does not create a routable multipoint-capable interface for dynamic routing updates.

  • ✗

    DMVPN phase 1 with only mGRE and no IPsec protection

    Why it's wrong here

    DMVPN with mGRE supports dynamic routing and multicast-like behavior, but omitting IPsec leaves traffic unprotected. The scenario implies a secure VPN, so plain mGRE does not meet the security expectation. Additionally, phase 1 has hub-and-spoke limitations for spoke-to-spoke traffic, making it a weaker fit than GRE over IPsec for this requirement.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.