mediumMultiple Choice
350-401 Practice Question: Runs the following command on Router R4: R4# show…
A network engineer runs the following command on Router R4:
R4# show interfaces tunnel 0
Tunnel0 is up, line protocol is up Hardware is Tunnel Internet address is 10.0.0.4/30 MTU 17916 bytes, BW 100 Kbit/sec, DLY 50000 usec, reliability 255/255, txload 1/255, rxload 1/255
Encapsulation TUNNEL, loopback not set
Keepalive not set Tunnel source 192.168.1.4, destination 192.168.2.4 Tunnel protocol/transport GRE/IP Key disabled, sequencing disabled Checksumming of packets disabled Last input never, output never, output hang never Last clearing of "show interface" counters never Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/0 (size/max) 5 minute input rate 0 bits/sec, 0 packets/sec 5 minute output rate 0 bits/sec, 0 packets/sec 0 packets input, 0 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 0 packets output, 0 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 unknown protocol drops 0 output buffer failures, 0 output buffers swapped out
Based on this output, what is true about this tunnel?
⚠ Common exam trap
Cisco often tests the misconception that a tunnel with zero packets or zero traffic is down, but the 'line protocol is up' status confirms it is operational regardless of traffic counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The tunnel is a GRE tunnel that is up and operational.
The output shows 'Tunnel protocol/transport GRE/IP', confirming this is a GRE tunnel. The interface status is 'up, line protocol is up', and the counters show zero errors, indicating the tunnel is fully operational. The lack of packet traffic does not indicate a failure; GRE tunnels can be up without active data flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The tunnel is using IPsec encryption.
Why it's wrong here
The interface output shows GRE/IP as the encapsulation protocol, not an IPsec transform set. IPsec would be indicated by the presence of crypto maps, security associations, or ESP/AH protocol references, and the tunnel mode would be configured as `tunnel mode ipsec ipv4` rather than `tunnel mode gre`. GRE itself provides only encapsulation, not confidentiality, so the tunnel is not using IPsec encryption.
- ✓
The tunnel is a GRE tunnel that is up and operational.
Why this is correct
The tunnel interface is up/up, meaning the interface administrative state is up and the line protocol is up. The protocol is GRE/IP, which confirms a Generic Routing Encapsulation tunnel configured over an IP transport network. An operational GRE tunnel only requires the tunnel source/destination to be reachable and the tunnel mode to be set to GRE; the tunnel being up/up independently verifies that it is operational, regardless of traffic flow.
- ✗
The tunnel is using MPLS over GRE.
Why it's wrong here
No MPLS labeling or `tag-switching` is present in the interface output; the protocol is plainly GRE/IP. MPLS over GRE would require the tunnel interface to have `mpls ip` enabled and would show MPLS-related encapsulation or forwarding information. Since none of those indicators appear, this is a standard GRE tunnel, not an MPLS-over-GRE setup.
- ✗
The tunnel is down because there are no packets.
Why it's wrong here
The tunnel being up/up is a state that is determined by the underlying IP reachability and the tunnel configuration, not by the presence or absence of packets. A tunnel can be fully operational with zero traffic passing through it; interface counters are independent of the operational status. Thus, the lack of packets does not imply the tunnel is down, and the output clearly shows the tunnel is operationally up.
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
GRE Tunnel
A GRE tunnel is a method that wraps one network protocol inside another, allowing data to travel across a network that might not support that protocol directly.
Key term
GRE
GRE (Generic Routing Encapsulation) is a tunneling protocol that encapsulates packets inside other packets to transport them across incompatible networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.