Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?

⚠ Common exam trap

The trap here is either forgetting to enable PFS or selecting a weak Diffie-Hellman group, which would not satisfy the requirement for perfect forward secrecy with strong encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14

To achieve AES-256 encryption and perfect forward secrecy, the transform-set must specify esp-aes 256 and esp-sha256-hmac, and the crypto map must include set pfs with a strong Diffie-Hellman group such as group14. This ensures that each new IPsec SA uses a unique key derived from a fresh Diffie-Hellman exchange, providing forward secrecy. The combination of these commands meets the security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp without set pfs

    Why it's wrong here

    The transform-set correctly specifies AES-256 and SHA-256, but omitting the set pfs command means perfect forward secrecy is not enabled. Without PFS, the same keying material may be reused across rekeys, which does not meet the requirement. The engineer explicitly wants PFS, so this configuration is incomplete and incorrect.

  • ✗

    crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group5

    Why it's wrong here

    While the transform-set is correct for AES-256 and SHA-256, the set pfs group5 command enables PFS using Diffie-Hellman group 5 (1536-bit), which is not as strong as group14 and may not be supported on all platforms. However, the primary issue is that the question does not specify a group, but group14 is the modern recommendation. Group5 is deprecated in many environments, so this option is less correct than using group14.

  • ✓

    crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14

    Why this is correct

    The transform-set with esp-aes 256 and esp-sha256-hmac specifies AES-256 encryption and SHA-256 HMAC for integrity. The set pfs group14 command in the crypto map enables perfect forward secrecy using Diffie-Hellman group 14 (2048-bit). This combination meets both requirements: AES-256 encryption and PFS. The transform-set and crypto map together define the IPsec policy for the tunnel.

  • ✗

    crypto ipsec transform-set TS esp-3des esp-md5-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group2

    Why it's wrong here

    This option uses 3DES encryption, which is not AES-256, and MD5 HMAC, which is weaker than SHA-256. While it does enable PFS with group2, the encryption algorithm does not meet the AES-256 requirement. Therefore, this configuration fails to provide the desired level of encryption strength and is not correct for the scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.