350-401 Security Practice Question
A network engineer is implementing IPsec VPN on a Cisco IOS XE router. The design requires that traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet be encrypted, while all other traffic should be sent unencrypted. The engineer creates a crypto ACL. Which action must be taken to ensure the crypto ACL correctly identifies the traffic to protect?
⚠ Common exam trap
The trap here is misunderstanding the implicit deny in a crypto ACL: placing an explicit deny before the permit would block the desired traffic from being encrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255' and ensure there is an implicit deny or an explicit deny for other traffic.
The crypto ACL must permit only the specific source and destination subnets that require encryption. Because ACLs have an implicit deny, traffic not matching the permit is not considered interesting and is sent unencrypted. This precisely implements the requirement to encrypt only traffic between 10.1.1.0/24 and 10.2.2.0/24.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the crypto ACL with 'permit ip any any' to ensure all traffic is encrypted, then use a route-map to exclude the non-interesting traffic.
Why it's wrong here
A crypto ACL with 'permit ip any any' would cause all traffic to be encrypted, which violates the requirement to send other traffic unencrypted. Route-maps cannot be used to exclude traffic from a crypto ACL; the ACL itself defines what is interesting. This approach would over-encrypt and potentially disrupt other communications.
- ✓
Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255' and ensure there is an implicit deny or an explicit deny for other traffic.
Why this is correct
The crypto ACL defines interesting traffic by permitting the specific source and destination subnets. Only traffic matching a permit statement is encrypted. An implicit deny at the end means other traffic is not matched and therefore not encrypted, which aligns with the requirement to send other traffic unencrypted. This is the correct way to define the VPN traffic selector.
- ✗
Configure the crypto ACL with 'deny ip any any' followed by 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'.
Why it's wrong here
Placing a deny statement before the permit would block all traffic from being considered interesting, and the permit would never be evaluated for matching because the deny any any matches first. This would prevent the desired subnets from being encrypted. The order of ACL entries is critical, and this configuration would break the VPN.
- ✗
Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 any' to cover all destinations from the source subnet, then rely on the VPN peer to filter.
Why it's wrong here
Permitting traffic from the source subnet to any destination would mark all outbound traffic from that subnet as interesting, causing it to be encrypted even when destined for other networks. The requirement is to encrypt only traffic to 10.2.2.0/24. This ACL is too broad and would not meet the design goal of selective encryption.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.