nerdexam
Cisco

350-701 · Question #888

A network engineer must establish a site-to-site VPN between two Cisco routers using IPsec. The engineer creates an extended access control list to permit the traffic, configures phase 1 and phase 2…

The correct answer is B. Apply the crypto map to the public interface. Attaching the crypto map to the router’s public-facing interface activates IPsec processing for traffic that matches the permit ACL, allowing the router to negotiate and bring up the VPN tunnel.

Submitted by carter_n· Mar 30, 2026Network Security

Question

A network engineer must establish a site-to-site VPN between two Cisco routers using IPsec. The engineer creates an extended access control list to permit the traffic, configures phase 1 and phase 2 of IPsec, and creates the crypto map for both routers. Which action completes the configuration?

Options

  • AEstablish the IPsec VPN tunnel.
  • BApply the crypto map to the public interface.
  • CConfigure the routers to perform NAT on the VPN network.
  • DPing one of the routers to verify network connectivity.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    73% (19)
  • C
    4% (1)
  • D
    15% (4)

Explanation

Attaching the crypto map to the router’s public-facing interface activates IPsec processing for traffic that matches the permit ACL, allowing the router to negotiate and bring up the VPN tunnel.

Topics

#Cisco IPsec VPN#Crypto map#Site-to-site VPN#VPN configuration

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice