350-401 Security Practice Question
A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?
⚠ Common exam trap
The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 proposal syntax, or placing proposal parameters under the policy command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14
The correct command to define an IKEv2 proposal with specific encryption, integrity, and DH group is under crypto ikev2 proposal, using the encryption, integrity, and group keywords. The policy command only references a proposal, and ISAKMP policy is for IKEv1. The keyring is for authentication, not proposal parameters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14
Why this is correct
This command sequence under crypto ikev2 proposal correctly specifies AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. In Cisco IOS, the IKEv2 proposal is configured with the encryption, integrity, and group keywords, and this syntax matches the required parameters for the proposal.
- ✗
crypto ikev2 keyring KEYRING peer SITE address 1.1.1.1 pre-shared-key local secret
Why it's wrong here
This command configures an IKEv2 keyring for pre-shared key authentication, not the proposal parameters. The keyring defines peer identities and keys, but it does not set encryption, integrity, or Diffie-Hellman group. Therefore, it does not satisfy the requirement to define the IKEv2 proposal with AES-256, SHA-256, and group 14.
- ✗
crypto isakmp policy 10 encryption aes 256 hash sha256 group 14
Why it's wrong here
This command configures an IKEv1 ISAKMP policy, not an IKEv2 proposal. The requirement specifies IKEv2, so using crypto isakmp policy would not meet the design. Additionally, the syntax for encryption in IKEv1 is 'encryption aes 256', which differs from IKEv2's 'encryption aes-cbc-256'.
- ✗
crypto ikev2 policy POLICY proposal PROP encryption aes-256 integrity sha256 group 14
Why it's wrong here
The crypto ikev2 policy command is used to associate a proposal with a policy, but the encryption, integrity, and group parameters belong in the proposal configuration, not in the policy command line. This syntax is invalid because the policy command does not accept those parameters directly; they must be configured under the proposal.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.