350-401 Security Practice Question
A network engineer is configuring an IPsec site-to-site VPN between two Cisco IOS-XE routers. The design requires that the data payload be encrypted and that the two peers authenticate each other using pre-shared keys without any certificate infrastructure. Which combination of IKEv2 parameters must be configured on both peers to establish the tunnel?
⚠ Common exam trap
Watch out — candidates often confuse IKEv1 constructs such as ISAKMP policies and crypto maps with the IKEv2 building blocks, or assuming a profile alone can hold the pre-shared key without a keyring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An IKEv2 proposal, an IKEv2 policy, an IKEv2 keyring, and an IKEv2 profile
IKEv2 on Cisco IOS-XE separates concerns: proposals define algorithms, policies select proposals based on match criteria, keyrings store pre-shared keys, and profiles bind identities, keyrings, and policies together. All four are required to negotiate the IKEv2 security association using PSK authentication with no PKI. The data-plane IPsec configuration (transform set and profile or map) is separate and layered on top of this control-plane configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An IKEv2 profile alone with inline pre-shared-key configuration
Why it's wrong here
An IKEv2 profile must reference a keyring and an IKEv2 policy to be functional; it cannot carry the PSK and algorithm definitions by itself. Without a proposal and policy, no encryption or integrity algorithms are offered during IKE_SA_INIT, and without a keyring, authentication fails. This incomplete configuration would not bring the tunnel up.
- ✗
An IKEv2 proposal, a transform set, and a dynamic crypto map
Why it's wrong here
A transform set specifies IPsec ESP encryption and hash for the data plane, not IKEv2 negotiation parameters, and a dynamic crypto map is only relevant for hub-and-spoke with dynamic peers. Critically, no keyring or profile is present, so pre-shared-key authentication cannot occur. The SA negotiation would fail during IKE_AUTH because the peer cannot be matched to a PSK.
- ✓
An IKEv2 proposal, an IKEv2 policy, an IKEv2 keyring, and an IKEv2 profile
Why this is correct
In IKEv2 on Cisco IOS-XE, a proposal defines the encryption, integrity, and PRF algorithms, a policy binds proposals to a match criterion, a keyring holds the pre-shared keys, and a profile ties the keyring to the peer and local identities and references the policy. All four components are needed to negotiate the IKEv2 SA using PSK authentication, making this the correct set.
- ✗
An ISAKMP policy, a crypto keyring with RSA signatures, and a crypto map
Why it's wrong here
An ISAKMP policy belongs to IKEv1 configuration, and RSA signatures require a PKI trustpoint, contradicting the requirement for pre-shared keys with no certificate infrastructure. A crypto map is used for IPsec data-plane policy, not for IKEv2 SA negotiation. This combination does not establish the IKEv2 pre-shared-key tunnel described.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.