Courseiva
Question 18 of 1,840
hardMultiple SelectObjective-mapped

350-401 Practice Question: Which three statements about IPsec VPNs are true?…

Which three statements about IPsec VPNs are true? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IKEv2 is more resilient to network changes than IKEv1 because it supports Dead Peer Detection (DPD) as a built-in feature.

IPsec VPNs can operate in transport mode (protecting payload only) or tunnel mode (protecting entire IP packet). IKEv2 is more robust than IKEv1, supporting EAP authentication and built-in DPD. AES is a symmetric encryption algorithm used for data confidentiality. SHA is used for integrity, not encryption. IKE uses UDP port 500, not TCP. ESP can provide both encryption and authentication, but authentication is optional in some implementations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IPsec transport mode encrypts the entire original IP packet, including the IP header.

    Why it's wrong here

    Incorrect because transport mode only encrypts the payload (transport layer and above), leaving the original IP header intact.

  • IKEv2 is more resilient to network changes than IKEv1 because it supports Dead Peer Detection (DPD) as a built-in feature.

    Why this is correct

    Correct because IKEv2 includes DPD as a standard mechanism to detect peer liveness, whereas IKEv1 requires separate configuration.

  • AES is a symmetric encryption algorithm commonly used in IPsec to provide data confidentiality.

    Why this is correct

    Correct because AES is a symmetric cipher used in IPsec for encrypting data; it is widely supported.

  • IKE uses TCP port 500 for key exchange and negotiation of security associations.

    Why it's wrong here

    Incorrect because IKE uses UDP port 500, not TCP.

  • ESP in tunnel mode can provide both encryption and authentication for the entire IP packet.

    Why this is correct

    Correct because ESP tunnel mode encrypts the entire original IP packet and adds a new IP header; authentication (integrity check) can be included.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 18, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.