350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco IOS router to support a site-to-site VPN using IPsec. The engineer wants to ensure that traffic from the local subnet 10.1.1.0/24 to the remote subnet 10.2.2.0/24 is encrypted. Which configuration is required to define the interesting traffic?
⚠ Common exam trap
The trap here is using a deny statement or 'any any' in the access list, which either excludes the desired traffic or includes too much, leading to incorrect encryption behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
The correct configuration uses an access list that permits IP traffic from the local subnet to the remote subnet and references it in the crypto map with 'match address'. This defines the interesting traffic that triggers the IPsec tunnel. The other options either deny the traffic, permit all traffic, or reverse the source and destination, which do not precisely meet the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 deny ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
Why it's wrong here
The access list in this option denies traffic from 10.1.1.0/24 to 10.2.2.0/24, which means that traffic will not be matched for encryption. IPsec uses permit statements in the access list to identify interesting traffic. A deny statement would exclude that traffic from encryption, which is the opposite of the requirement.
- ✗
crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip any any
Why it's wrong here
This access list permits all IP traffic, which would cause all traffic to be encrypted, not just the traffic between the specified subnets. While it would include the desired traffic, it is overly broad and would also encrypt traffic that should not be encrypted, such as Internet-bound traffic. The requirement is to encrypt only traffic between the two subnets.
- ✓
crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
Why this is correct
This configuration defines an access list (101) that matches traffic from 10.1.1.0/24 to 10.2.2.0/24, and references it in the crypto map with the 'match address' command. This access list identifies the interesting traffic that will be encrypted by IPsec. The crypto map also sets the peer and transform set, completing the IPsec configuration.
- ✗
crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255
Why it's wrong here
This access list matches traffic from the remote subnet to the local subnet, which is the reverse direction. While IPsec is bidirectional, the crypto map access list is typically configured to match traffic from local to remote. Using the reverse might still work if the remote peer is configured symmetrically, but it is not the standard or recommended configuration. The requirement is to encrypt traffic from local to remote.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.