Courseiva
mediumMultiple Choice

350-401 Practice Question: Runs the following command on Router R7: R7# show…

A network engineer runs the following command on Router R7:

R7# show crypto ikev2 sa detail

IKEv2 SAs:

Session-id:1, Status:UP-ACTIVE, IKE count:1, Child count:1

Tunnel-id Local Remote Status Role 1 10.1.1.1/4500 10.2.2.2/4500 READY INITIATOR Encr: AES-CBC 256, Hash: SHA256, DH Grp:14, Auth sign: PSK, Auth verify: PSK Life/Active Time: 86400/3600 sec

Child SA: Local selector 10.1.1.0/0 - 10.1.1.255/65535 Remote selector 10.2.2.0/0 - 10.2.2.255/65535 ESP spi in/out: 0x12345678/0x87654321

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the interpretation of 'show crypto ikev2 sa detail' output, and the trap here is that candidates may misinterpret 'READY' as a failure state or confuse 'Auth sign: PSK' with RSA signatures, especially when the output also shows encryption and hash algorithms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The tunnel is using pre-shared keys for authentication.

The output shows 'Auth sign: PSK' and 'Auth verify: PSK', which explicitly indicates that pre-shared keys (PSK) are used for IKEv2 authentication. The status 'READY' and 'UP-ACTIVE' confirm the SA is operational, not failed. Therefore, option B is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IKEv2 SA is in a failed state because it is READY.

    Why it's wrong here

    In Cisco IKEv2, the SA state of 'READY' is a normal, operational state that indicates the IKEv2 SA has been successfully established and is actively usable for securing traffic. It is not an error or failure state; rather, it reflects that both endpoints have completed the IKE_SA_INIT and IKE_AUTH exchanges and have installed the IPsec SAs. A failed SA would typically show a state such as 'DELETED', 'LARVAL', or be absent from the output entirely, not 'READY'.

  • ✓

    The tunnel is using pre-shared keys for authentication.

    Why this is correct

    The output directly shows 'Auth sign: PSK' and 'Auth verify: PSK', which are the IKEv2 authentication fields that specify the integrity/authentication algorithm used during the IKE_AUTH exchange. When both fields display 'PSK', the tunnel is unambiguously using pre-shared keys for authentication, meaning both peers derive the same symmetric key from a shared secret. This is a common, low-overhead authentication method in IPsec VPNs, and the Cisco CLI explicitly reports it in the 'show crypto ikev2 sa' or 'show crypto ikev2 profile' output.

  • ✗

    The tunnel is using RSA signatures for authentication.

    Why it's wrong here

    RSA signature authentication in IKEv2 would be indicated by 'Auth sign: RSA' (or 'RSA-SIG') and 'Auth verify: RSA' in the corresponding command output, as the router would use its RSA private key to sign the key exchange payload. In the given output, both fields show 'PSK', which is mutually exclusive with RSA signatures for the same Security Association because the authentication method is negotiated during IKEv2's initial exchange. Therefore, stating that the tunnel uses RSA signatures directly contradicts the observed authentication parameters and is incorrect.

  • ✗

    The IKEv2 SA has expired because the life time is 86400 seconds.

    Why it's wrong here

    The IKEv2 SA lifetime is the maximum duration (86400 seconds) or traffic volume it can exist before rekeying or expiration, but the SA only reaches that point after being active for that full time. The output also includes an active time of 3600 seconds, which is far below the lifetime threshold, meaning the SA is still well within its valid operational window. Furthermore, IKEv2 implementations proactively rekey before the hard lifetime expires, so an SA showing a remaining lifetime is not considered expired.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.