exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 56 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 56
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.

Based on the phase 2 configuration shown in the exhibit, which configuration change will bring phase 2 up?

  • A. On Remote-FortiGate, set Seconds to 43200.
  • B. On HQ-FortiGate, set Encryption to AES256.
  • C. On HQ-FortiGate, enable Diffie-Hellman Group 2.
  • D. On HQ-FortiGate, enable Auto-negotiate.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
millerry
1 year, 4 months ago
Selected Answer: B
B. ref FortiGate 7.2 Infrastructure page 263
upvoted 1 times
...
raydel92
1 year, 7 months ago
Selected Answer: B
B. On HQ-FortiGate, set Encryption to AES256. Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 1 times
...
Leodoro
1 year, 8 months ago
Selected Answer: B
B is correct. When key lifetime is different, FortiGate chooses the lower one. Diffie Helman group needs only one that matches. The authentication proposals need one matching, which there isnt. That makes is B.
upvoted 4 times
...
darkstar15
1 year, 9 months ago
La respuesta es B por que lo esta manejando el escenario como una "falla en fase 2". 1) Confirm if the Encryption and Hashing algorithms match on both receiver and initiator. 2) Check if PFS is enabled, if yes, make sure the configuration is matched on both the units. 3) Make sure, if the quick mode selectors (interesting traffic) is matching on both units.
upvoted 2 times
...
A_Roger
1 year, 9 months ago
Selected Answer: C
I think the correct is C. DH is different between HQ and Spoke. AES is matching on both sides
upvoted 1 times
Garry_G
1 year, 8 months ago
IPSEC will work as long as there is an overlap in the configs ... if one had only 5, the other only 2, you'd be correct. But as both have 5 available, they can still initiate Phase 2 using it. At least if both share the same encryption/signature combos, so B ...
upvoted 2 times
...
A_Roger
1 year, 9 months ago
AES are different. Right is B
upvoted 2 times
...
...
Sjiht87
2 years ago
Selected Answer: B
B is Correct set AES256 on both sides in order to complete Phase2
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago