mediumMultiple Select
350-401 Practice Question: Which three statements about FlexVPN are true?…
Which three statements about FlexVPN are true? (Choose three.)
⚠ Common exam trap
350-401 often tests the DMVPN-versus-FlexVPN distinction, baiting candidates into selecting NHRP as a FlexVPN feature because NHRP is so strongly associated with dynamic spoke discovery in DMVPN — remember NHRP is IKEv1/DMVPN, not FlexVPN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FlexVPN uses IKEv2 as its underlying key exchange protocol.
Option A is correct because FlexVPN is built on IKEv2, which handles the key exchange and security association negotiation for both IPsec and FlexVPN tunnels. Option B is correct because FlexVPN is a unified framework that supports site-to-site, hub-and-spoke, and remote-access VPN topologies using the same IKEv2/IPsec infrastructure. Option D is correct because FlexVPN supports multiple authentication methods, including digital certificates (RSA/ECDSA) and pre-shared keys, as well as EAP-based methods. Option C is incorrect because FlexVPN does not require a dedicated AAA server; local authentication or certificates can be used, and AAA is optional. Option E is incorrect because NHRP is used by DMVPN, not FlexVPN; FlexVPN uses IKEv2 routing and IPsec to establish tunnels without NHRP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FlexVPN uses IKEv2 as its underlying key exchange protocol.
Why this is correct
FlexVPN relies exclusively on IKEv2 for tunnel negotiation, unlike legacy DMVPN deployments that commonly use IKEv1. This satisfies the stem's requirement for a true FlexVPN statement, since IKEv2 provides the mandatory key exchange underpinning its unified configuration model, native redundancy, and per-peer policy flexibility.
- ✓
FlexVPN supports both site-to-site and remote access VPN topologies.
Why this is correct
FlexVPN unifies IKEv2-based tunnels under a single framework, so the same configuration constructs serve both site-to-site and remote-access topologies. This satisfies the scenario's requirement that one technology cover both deployment models without separate legacy designs such as DMVPN or Easy VPN.
- ✗
FlexVPN requires a dedicated AAA server for all authentication functions.
Why it's wrong here
FlexVPN can authenticate using local credentials, certificates or AAA, so a dedicated AAA server is not mandatory. It tempts because enterprise deployments commonly centralise authorisation on AAA, but the protocol itself supports local and PKI methods, making the requirement absolute only in specific designs.
- ✓
FlexVPN can use digital certificates or pre-shared keys for authentication.
Why this is correct
FlexVPN's IKEv2 negotiation supports certificate-based authentication and pre-shared keys as peer credentials. This satisfies the scenario's requirement for flexible authentication, since either method can be selected per tunnel or profile without changing the underlying FlexVPN architecture.
- ✗
FlexVPN uses NHRP to dynamically discover spoke routers and establish direct tunnels.
Why it's wrong here
FlexVPN is IKEv2-based and uses routing or shortcut switching for spoke-to-spoke connectivity, not NHRP, which belongs to DMVPN. It tempts because DMVPN's hub-and-spoke dynamic tunnel model resembles FlexVPN's, but FlexVPN achieves direct spoke tunnels through IKEv2 shortcut switching instead.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.