In the "crypto isakmp key ... address " command, the address must be of the IP address of the other end (which is 200.1.1.3 in this case) so Option A and Option B are correct. The difference between these two options are in the hash SHA or MD5 method but both of them can be used although SHA is better than MD5 so we choose Option A the best answer. Note: Cisco no longer recommends using 3DES, MD5 and DH groups 1, 2 and 5. Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_imgmt/configuration/xe-16- 5/sec-ipsec-management-xe-16-5-book/sec-ipsec-usability-enhance.html