exam questions

Exam NSE7_NST-7.2 All Questions

View all questions & answers for the NSE7_NST-7.2 exam

Exam NSE7_NST-7.2 topic 1 question 6 discussion

Actual exam question from Fortinet's NSE7_NST-7.2
Question #: 6
Topic #: 1
[All NSE7_NST-7.2 Questions]

Which statement about IKE and IKE NAT-T is true?

  • A. IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.
  • B. IKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2.
  • C. They each use their own IP protocol number.
  • D. They both use UDP as their transport protocol and the port number is configurable.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TrX
4 months, 3 weeks ago
Selected Answer: D
IKE (Internet Key Exchange): The protocol used to establish and manage security associations (SAs) for IPsec.   Uses UDP as the transport protocol. The port number for IKE is typically 500.   Configurable to use different port numbers for security reasons. IKE NAT-T (Network Address Translation Traversal): An extension of IKE that allows IPsec to work correctly in environments where one or both endpoints are behind Network Address Translators (NATs). Also uses UDP as the transport protocol. Port number is configurable for IKE NAT-T as well, allowing flexibility in deployment scenarios.
upvoted 1 times
...
billmondr98
5 months, 3 weeks ago
Selected Answer: D
Tanto IKE como IKE NAT-T usan UDP como protocolo de transporte, y los números de puerto son configurables en FortiGate (aunque los valores predeterminados son 500 para IKE y 4500 para NAT-T).
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...