Courseiva
mediumMultiple SelectObjective-mapped

350-401 Practice Question: Which two statements about IPsec IKEv2 are true?…

Which two statements about IPsec IKEv2 are true? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP 4500 for NAT traversal.

IKEv2 uses UDP port 500 and 4500, supports EAP authentication, and is more robust than IKEv1. It does not use TCP, and it supports multiple simultaneous SAs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP 4500 for NAT traversal.

    Why this is correct

    Correct because IKEv2 uses UDP 500 and 4500 for NAT-T.

  • IKEv2 supports EAP authentication for remote access VPNs.

    Why this is correct

    Correct because IKEv2 natively supports EAP for client authentication.

  • IKEv2 uses TCP port 500 for control plane messages.

    Why it's wrong here

    Incorrect because IKEv2 uses UDP, not TCP.

  • IKEv2 requires a separate IPsec SA for each direction of traffic.

    Why it's wrong here

    Incorrect because IKEv2 creates a pair of SAs (one per direction) as part of the same exchange, but this is not a separate requirement.

  • IKEv2 is not compatible with certificate-based authentication.

    Why it's wrong here

    Incorrect because IKEv2 fully supports certificate-based authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,175-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.