N10-009 Static route Practice Question
A network engineer has established an IPsec VPN tunnel between a branch office (10.0.0.0/24) and the main office (192.168.10.0/24). The tunnel shows as up and active, but users at the branch office cannot ping the main office server at 192.168.10.10. The main office can ping the branch office gateway successfully. What is the most likely cause of this issue?
⚠ Common exam trap
The N10-009 exam often tests the distinction between a tunnel being 'up' (IPsec SAs established) and traffic actually flowing correctly, leading candidates to incorrectly assume that a working tunnel guarantees bidirectional reachability without verifying routing or crypto ACLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incorrect static route on the branch router for the 192.168.10.0/24 network
The tunnel is up and active, and the main office can ping the branch office gateway, which confirms that Phase 1 and Phase 2 of IPsec are correctly negotiated and that the tunnel is passing traffic from the main office toward the branch. However, branch users cannot reach 192.168.10.10, indicating that return traffic from the branch is not being routed into the tunnel. The most likely cause is that the branch router lacks a static route for 192.168.10.0/24 pointing to the tunnel interface (or the IPsec virtual interface), so packets from the branch destined for the main office are sent out the wrong interface or dropped instead of being encrypted and forwarded through the VPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mismatched encryption algorithms between the two VPN peers
Why it's wrong here
If encryption algorithms were mismatched, the tunnel would not establish. Since the tunnel is up, this is not the issue.
When this WOULD be correct
A network engineer configures an IPsec VPN between two sites, but the tunnel fails to come up. The logs show phase 2 negotiation failures. In this scenario, mismatched encryption algorithms (e.g., AES vs. 3DES) would be the likely cause.
- ✓
Incorrect static route on the branch router for the 192.168.10.0/24 network
Why this is correct
A route pointing to the tunnel interface or the remote VPN peer is necessary for traffic from the branch to reach the main office LAN.
- ✗
Firewall on the main office server blocking ICMP
Why it's wrong here
While possible, the main office can ping the branch gateway, and if the tunnel is up, firewall rules affecting ICMP are less likely the root cause compared to missing routing.
When this WOULD be correct
In a scenario where the VPN tunnel is up, the branch can ping the main office gateway, but pings to the main office server fail, and the main office server has a firewall that blocks ICMP from the branch subnet. The correct answer would be firewall blocking ICMP.
- ✗
Incorrect IKE authentication settings
Why it's wrong here
IKE authentication issues would prevent the tunnel from being established; since the tunnel is active, this is not the cause.
When this WOULD be correct
A network engineer configures an IPsec VPN but the tunnel fails to come up. The logs show IKE negotiation errors. In this scenario, incorrect IKE authentication settings (e.g., mismatched pre-shared keys or certificates) would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Incorrect static route on the branch router for the 192.168.10.0/24 networkCorrect answer▾
Why this is correct
A route pointing to the tunnel interface or the remote VPN peer is necessary for traffic from the branch to reach the main office LAN.
✗Mismatched encryption algorithms between the two VPN peersWrong answer — click to see why▾
Why this is wrong here
Mismatched encryption algorithms would prevent the IPsec tunnel from establishing or staying up, but the question states the tunnel is up and active, so this is not the issue.
★ When this WOULD be the correct answer
A network engineer configures an IPsec VPN between two sites, but the tunnel fails to come up. The logs show phase 2 negotiation failures. In this scenario, mismatched encryption algorithms (e.g., AES vs. 3DES) would be the likely cause.
Why candidates choose this
Candidates often associate VPN problems with encryption mismatches, overlooking that a working tunnel implies successful algorithm negotiation.
✗Firewall on the main office server blocking ICMPWrong answer — click to see why▾
Why this is wrong here
The main office can ping the branch office gateway, indicating the tunnel is working and ICMP is not blocked at the main office server. The issue is that branch users cannot reach the server, pointing to a routing problem on the branch side, not a firewall rule.
★ When this WOULD be the correct answer
In a scenario where the VPN tunnel is up, the branch can ping the main office gateway, but pings to the main office server fail, and the main office server has a firewall that blocks ICMP from the branch subnet. The correct answer would be firewall blocking ICMP.
Why candidates choose this
Candidates often default to firewall issues when pings fail, overlooking that the successful ping from main office to branch gateway confirms the tunnel and ICMP are functional. They may not consider asymmetric routing or missing routes.
✗Incorrect IKE authentication settingsWrong answer — click to see why▾
Why this is wrong here
Incorrect IKE authentication settings would prevent the IPsec tunnel from establishing, but the question states the tunnel is up and active, indicating IKE phase 1 and phase 2 completed successfully.
★ When this WOULD be the correct answer
A network engineer configures an IPsec VPN but the tunnel fails to come up. The logs show IKE negotiation errors. In this scenario, incorrect IKE authentication settings (e.g., mismatched pre-shared keys or certificates) would be the correct answer.
Why candidates choose this
Candidates may confuse authentication issues with routing issues, assuming that any connectivity problem in a VPN must be due to security parameter mismatches, even when the tunnel status indicates otherwise.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Physical Network Infrastructure
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
ICMP
ICMP is a network-layer protocol used by network devices to send error messages and operational information about network connectivity.
About these practice questions
Courseiva writes every N10-009 question from scratch — 472 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.