mediumMultiple Choice
350-401 Practice Question: Given the following configuration on a Cisco…
Given the following configuration on a Cisco IOS-XE router:
interface Tunnel100 ip address 10.0.0.1 255.255.255.252
tunnel source GigabitEthernet0/0/0 tunnel destination 192.168.1.1 tunnel mode ipsec ipv4 tunnel protection ipsec profile MYPROFILE
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between 'tunnel mode ipsec ipv4' (VTI) and 'tunnel mode gre ip' with IPsec protection, where candidates mistakenly assume any tunnel with IPsec protection must be a GRE tunnel, but the 'tunnel mode' command determines the encapsulation type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It creates a VTI (Virtual Tunnel Interface) that encrypts all traffic routed into the tunnel using IPsec.
The configuration creates a Virtual Tunnel Interface (VTI) that encrypts all traffic routed into the tunnel using IPsec. The 'tunnel mode ipsec ipv4' command explicitly sets the tunnel to operate in IPsec tunnel mode (not GRE), and 'tunnel protection ipsec profile MYPROFILE' applies IPsec encryption directly to the tunnel interface. This is a standard static VTI configuration, which encrypts any IPv4 traffic that is routed into the tunnel without requiring a separate crypto map.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It creates a GRE tunnel with IPsec encryption.
Why it's wrong here
The command in question, tunnel mode ipsec ipv4, does not create a GRE tunnel. GRE tunnels are configured with tunnel mode gre (or gre multipoint) and rely on a separate IPsec protection mechanism, such as a crypto map applied to the physical interface or an IPsec profile bound to the GRE tunnel. The mode ipsec ipv4 is specifically used for VTI (Virtual Tunnel Interface) tunnels, which are route-based and do not add a GRE header. Therefore, while GRE-over-IPsec is a valid design, it is not what this tunnel mode creates.
- ✓
It creates a VTI (Virtual Tunnel Interface) that encrypts all traffic routed into the tunnel using IPsec.
Why this is correct
Tunnel mode ipsec ipv4 creates a static VTI (Virtual Tunnel Interface), which is a route-based IPsec VPN interface. All traffic routed into this tunnel gets encrypted and encapsulated directly into IPsec using the parameters defined in the referenced IPsec profile. Unlike GRE, a VTI has no extra GRE header, and unlike a crypto map, it allows routing protocols and policy-based routing to decide what to protect, making it a clean, scalable site-to-site VPN solution.
- ✗
It creates a DMVPN phase 1 tunnel with mGRE.
Why it's wrong here
DMVPN (Dynamic Multipoint VPN) relies on mGRE (multipoint GRE, configured as tunnel mode gre multipoint) and NHRP (Next Hop Resolution Protocol) to dynamically build spoke-to-spoke tunnels, not on tunnel mode ipsec ipv4. While DMVPN does use IPsec to encrypt traffic, the tunnel interface itself must be mGRE to support multipoint connections and dynamic peer discovery. Setting tunnel mode ipsec ipv4 creates a static point-to-point VTI, which lacks the multipoint capability required for DMVPN, so this cannot describe a DMVPN phase 1 deployment.
- ✗
It creates a L2TPv3 tunnel for layer 2 transport.
Why it's wrong here
L2TPv3 (Layer 2 Tunneling Protocol version 3) is used for layer 2 transport, such as carrying Ethernet frames or VLANs over an IP network, and it requires the command tunnel mode l2tpv3. In contrast, tunnel mode ipsec ipv4 creates a layer 3 VTI that encrypts and forwards IP packets, not layer 2 frames. Although L2TPv3 can be combined with IPsec for security, the tunnel encapsulation mode is fundamentally different, and the command referenced in the question is exclusively related to route-based IPsec VTIs, not layer 2 pseudowires.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
GRE
GRE (Generic Routing Encapsulation) is a tunneling protocol that encapsulates packets inside other packets to transport them across incompatible networks.
Key term
IPsec Tunnel
An IPsec tunnel is a secure, encrypted connection between two network devices that protects data as it travels across the internet or another untrusted network.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.