350-401 Security Practice Question
A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?
⚠ Common exam trap
Candidates often confuse the command that binds a trustpoint to an IKEv2 profile with the command that matches certificate fields or configures PSK authentication, leading to an incomplete or incorrect configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.
IKEv2 certificate-based authentication requires a PKI trustpoint to be associated with the IKEv2 profile. The 'pki trustpoint' command under the IKEv2 profile binds the trustpoint, enabling the router to use certificates for authentication. This must be configured on both peers. Other commands like 'match certificate' are used for certificate map matching, and keyrings are for PSK authentication, neither of which satisfies the certificate requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crypto ikev2 proposal <name> and then encryption aes-cbc-256 under the proposal.
Why it's wrong here
The 'crypto ikev2 proposal' command defines the encryption, integrity, and Diffie-Hellman group parameters for the IKEv2 SA. It does not handle authentication or trustpoint selection. While a proposal is necessary for IKEv2, it does not specify how peers authenticate, so it cannot fulfill the certificate-based authentication requirement.
- ✓
crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.
Why this is correct
Within an IKEv2 profile, the 'pki trustpoint' command specifies which PKI trustpoint the router will use for certificate-based authentication. This is the correct way to bind a trustpoint to an IKEv2 profile. Both routers must have this configured to present and validate certificates during IKEv2 negotiation, satisfying the certificate-based authentication requirement.
- ✗
crypto ikev2 profile <name> and then match certificate <map-name> under the profile.
Why it's wrong here
The 'match certificate' command under an IKEv2 profile is used for certificate map matching, which allows the router to select a trustpoint based on certificate fields. However, it does not directly specify the trustpoint for authentication. The trustpoint itself must be referenced using the 'identity local dn' or 'pki trustpoint' command within the profile, making this option incomplete for the requirement.
- ✗
crypto ikev2 keyring <name> and then pre-shared-key <key> under the keyring.
Why it's wrong here
The 'crypto ikev2 keyring' and 'pre-shared-key' commands configure pre-shared key authentication, not certificate-based authentication. While keyrings are used in IKEv2 for PSK authentication, the scenario explicitly requires certificate-based authentication. Using a keyring would not meet the security policy and would leave the VPN using a less secure authentication method.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.