350-401 Security Practice Question
A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator needs to ensure that the VPN traffic is encrypted and authenticated. Which two protocols are used in IPsec to provide encryption and authentication? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse tunneling protocols like GRE or L2TP with IPsec protocols, or thinking that SSL is part of IPsec when it is a separate security protocol.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AH
ESP and AH are the two core IPsec protocols. ESP provides encryption and optional authentication, while AH provides authentication and integrity but no encryption. Together or separately, they can secure VPN traffic. The other options are tunneling or security protocols not part of IPsec's native encryption and authentication mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
L2TP
Why it's wrong here
Layer 2 Tunneling Protocol (L2TP) is a tunneling protocol that does not provide encryption or authentication on its own. It is often used with IPsec for VPNs, but L2TP itself is not an IPsec protocol and does not provide the required security services.
- ✗
SSL
Why it's wrong here
Secure Sockets Layer (SSL) is used for securing web traffic and can be used in SSL VPNs, but it is not an IPsec protocol. The question specifically asks for IPsec protocols used to provide encryption and authentication, so SSL is not correct in this context.
- ✓
AH
Why this is correct
Authentication Header (AH) is an IPsec protocol that provides authentication and integrity but does not provide encryption. It ensures that the data is from a legitimate source and has not been altered. In the scenario, AH can be used for authentication, but it does not encrypt the traffic.
- ✗
GRE
Why it's wrong here
Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate various protocols but does not provide encryption or authentication by itself. It is often used with IPsec to add encryption, but GRE alone does not meet the requirement for encrypted and authenticated VPN traffic.
- ✓
ESP
Why this is correct
Encapsulating Security Payload (ESP) is an IPsec protocol that provides confidentiality through encryption and optionally authentication. It is used to encrypt the payload and can also provide data integrity and authentication. In the scenario, ESP is essential for ensuring the VPN traffic is encrypted.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.