mediumMultiple Choice
350-401 Practice Question: Examine the following IPsec configuration…
Examine the following IPsec configuration snippet:
crypto ikev2 proposal IKEV2_PROP
encryption aes-cbc-256 integrity sha256 group 14 !
crypto ikev2 policy IKEV2_POL
proposal IKEV2_PROP !
crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac
mode tunnel !
crypto ipsec profile IPSEC_PROF
set transform-set TSET set ikev2-profile IKEV2_POL
Which statement about this configuration is true?
⚠ Common exam trap
Cisco often tests the distinction between the IKEv2 proposal (control plane) and the IPsec transform set (data plane), and the trap here is that candidates might confuse the 'set ikev2-profile' command syntax or assume PFS is mandatory, when in fact the configuration is valid as shown.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The transform set uses ESP with AES-256 encryption and SHA-256 HMAC for authentication.
The transform set explicitly uses 'esp-aes 256' for encryption and 'esp-sha256-hmac' for authentication, which matches the description of ESP with AES-256 encryption and SHA-256 HMAC. The IKEv2 proposal and profile are correctly configured, and the 'mode tunnel' command ensures the transform set operates in tunnel mode, which is appropriate for site-to-site VPNs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The transform set uses ESP with AES-256 encryption and SHA-256 HMAC for authentication.
Why this is correct
The transform set is correctly defined. The commands `esp-aes 256` and `esp-sha256-hmac` under `crypto ipsec transform-set` specify the Encapsulating Security Payload (ESP) with AES-256 for confidentiality and the SHA-256 HMAC variant for integrity and authentication. This is a valid and secure combination for a site-to-site IPsec VPN. The statement matches the configuration, making it the correct answer.
- ✗
The IKEv2 proposal uses AES-256, SHA-256, and DH group 14, but the IPsec profile will not apply because the ikev2-profile command is missing the 'set' keyword.
Why it's wrong here
The `set` keyword is indeed present. In Cisco IOS, the IPsec profile references the IKEv2 parameter set using the command `set ikev2-profile IKEV2_POL`; omitting `set` would make the command invalid, but here it is explicitly listed. Additionally, there is no requirement that the IKEv2 policy name differ from the profile name—they can be identical. Therefore the IPsec profile will apply as intended.
- ✗
The transform set is configured in transport mode, which is incorrect for site-to-site VPN.
Why it's wrong here
This claim is false because the transform set is not in transport mode. The configuration explicitly includes the `mode tunnel` command, which overrides the default transport mode and sets the transform set to use IPsec tunnel mode—essential for site-to-site VPNs that encapsulate the entire original IP packet. Transport mode is typically used only for end-to-end host communications or within a GRE-protected tunnel, not for classic site-to-site IPsec deployments. Thus, this option is wrong.
- ✗
The IPsec profile is incomplete because it does not include a PFS (Perfect Forward Secrecy) setting.
Why it's wrong here
PFS (Perfect Forward Secrecy) is not a required element of a valid IPsec profile. In Cisco IOS, PFS is enabled via the `set pfs` command within the crypto map or IPsec profile; while it improves security by ensuring session keys are not derived from persistent keys, its absence does not make the configuration incomplete. The profile can still be applied and the VPN will function correctly. Therefore, claiming the profile is incomplete for lacking PFS is incorrect.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.