Courseiva
mediumMultiple Choice

350-401 Practice Question: Runs the following command on Router R2: R2# show…

A network engineer runs the following command on Router R2:

R2# show crypto ipsec sa peer 10.2.2.2
interface: Tunnel0
    Crypto map tag: CMAP, local addr 10.1.1.2

protected vrf: (none) local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (10.2.2.0/255.255.255.0/0/0) current_peer 10.2.2.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 1500, #pkts encrypt: 1500, #pkts digest: 1500 #pkts decaps: 1200, #pkts decrypt: 1200, #pkts verify: 1200 #pkts compressed: 0, #pkts decompress: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the ability to interpret IPsec SA counters, where candidates mistakenly assume that any non-zero counters mean the tunnel is fully functional, ignoring the critical asymmetry between outbound and inbound packet counts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

There is a routing problem causing packets to be dropped in one direction.

The output shows 1500 packets encapsulated and encrypted (outbound) but only 1200 packets decapsulated and decrypted (inbound). This asymmetry indicates that 300 packets were sent but not returned, which points to a routing issue causing packets to be dropped in one direction. A properly functioning IPsec tunnel should have roughly symmetric packet counts in both directions if traffic is bidirectional.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IPsec tunnel is functioning correctly with no issues.

    Why it's wrong here

    The IPsec tunnel is not functioning correctly because the encaps and decaps packet counters are mismatched. In a healthy tunnel, these counters should be approximately equal, as every packet encrypted and sent should be decrypted and received by the peer. A significant discrepancy indicates loss or one-way traffic, so the tunnel has an active problem.

  • ✓

    There is a routing problem causing packets to be dropped in one direction.

    Why this is correct

    A routing problem is indicated by the higher encaps count compared to decaps count. This means packets are being encrypted and sent into the tunnel, but fewer packets are arriving and being decrypted from the remote peer. Typically, this is caused by missing return routes, asymmetric routing, or firewall rules that drop encrypted traffic in one direction, leading to packet loss.

  • ✗

    The tunnel is using compression, as shown by the compress counters.

    Why it's wrong here

    The compress counters are zero, which proves the tunnel is not using compression. IPsec compression (such as IPComp) would increment these counters for each packet processed. Since they remain at zero, no compression is active, so this option is clearly incorrect.

  • ✗

    The remote peer is not responding to IKE requests.

    Why it's wrong here

    The remote peer is definitely responding to IKE requests because the tunnel is established and decaps counters show that packets are being received and processed. If the remote peer were not responding to IKE, the tunnel would not exist, and both encaps and decaps counters would be zero. The presence of decapsulated packets rules out an IKE-level failure.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.