Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to support a site-to-site VPN using IPsec. The engineer wants to ensure that traffic from the local subnet 10.1.1.0/24 to the remote subnet 10.2.2.0/24 is encrypted. Which configuration is required to define the interesting traffic?

⚠ Common exam trap

The trap here is using a deny statement or 'any any' in the access list, which either excludes the desired traffic or includes too much, leading to incorrect encryption behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255

The correct configuration uses an access list that permits IP traffic from the local subnet to the remote subnet and references it in the crypto map with 'match address'. This defines the interesting traffic that triggers the IPsec tunnel. The other options either deny the traffic, permit all traffic, or reverse the source and destination, which do not precisely meet the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 deny ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255

    Why it's wrong here

    The access list in this option denies traffic from 10.1.1.0/24 to 10.2.2.0/24, which means that traffic will not be matched for encryption. IPsec uses permit statements in the access list to identify interesting traffic. A deny statement would exclude that traffic from encryption, which is the opposite of the requirement.

  • ✗

    crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip any any

    Why it's wrong here

    This access list permits all IP traffic, which would cause all traffic to be encrypted, not just the traffic between the specified subnets. While it would include the desired traffic, it is overly broad and would also encrypt traffic that should not be encrypted, such as Internet-bound traffic. The requirement is to encrypt only traffic between the two subnets.

  • ✓

    crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255

    Why this is correct

    This configuration defines an access list (101) that matches traffic from 10.1.1.0/24 to 10.2.2.0/24, and references it in the crypto map with the 'match address' command. This access list identifies the interesting traffic that will be encrypted by IPsec. The crypto map also sets the peer and transform set, completing the IPsec configuration.

  • ✗

    crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255

    Why it's wrong here

    This access list matches traffic from the remote subnet to the local subnet, which is the reverse direction. While IPsec is bidirectional, the crypto map access list is typically configured to match traffic from local to remote. Using the reverse might still work if the remote peer is configured symmetrically, but it is not the standard or recommended configuration. The requirement is to encrypt traffic from local to remote.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.