nerdexam
Cisco

350-701 · Question #671

350-701 Question #671: Real Exam Question with Answer & Explanation

Sign in or unlock 350-701 to reveal the answer and full explanation for question #671. The question stem and answer options stay visible for context.

Submitted by yaw92· Mar 30, 2026Secure Network Access, Visibility, and Enforcement

Question

Refer to the exhibit. An administrator is configuring a VPN tunnel on a Cisco router. The information provided by the administrator of the remote end of the VPN tunnel was that IKEv1 is the tunnel protocol with a preshared key of C1$c0463835440!. The encryption for both phases is AES and the hash for both phases is SHA-256. The source subnet is 10.10.10.x/24 and the destination subnet is 10.10.20.x/24. The local device cannot establish a VPN tunnel and the debug message shown here is seen in the log file. What must be verified to correct the configuration?

Exhibit

350-701 question #671 exhibit

Options

  • AEnsure that the IKE version is identical on both ends
  • BEnsure that the ISAKMP policy configuration is identical on both ends
  • CEnsure that the preshared key is identical on both ends
  • DEnsure that the ACLs that define interesting traffic are symmetrical on both ends

Unlock 350-701 to see the answer

You've previewed enough free 350-701 questions. Unlock 350-701 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Cisco VPN#IPsec VPN#ISAKMP policy#VPN troubleshooting
Full 350-701 Practice