exam questions

Exam FCSS_NST_SE-7.4 All Questions

View all questions & answers for the FCSS_NST_SE-7.4 exam

Exam FCSS_NST_SE-7.4 topic 1 question 22 discussion

Actual exam question from Fortinet's FCSS_NST_SE-7.4
Question #: 22
Topic #: 1
[All FCSS_NST_SE-7.4 Questions]

Refer to the exhibits, which contain the partial configurations of two VPNs on FortiGate.

An administrator has configured two VPNs for two different user groups. Users who are in the Users-2 group are not able to connect to the VPN. After running a diagnostics command, the administrator discovers that FortiGate is not matching the user-2 VPN for members of the Users-2 group.
Which two changes must the administrator make to fix the issue? (Choose two.)

  • A. Change to aggressive mode on both VPNs.
  • B. Enable XAuth on both VPNs.
  • C. Use different pre-shared keys on both VPNs.
  • D. Set up specific peer IDs on both VPNs.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d9eeb6d
1 week, 4 days ago
Selected Answer: AD
FCSS - Network Security Support Engineer 7.4 Sample Questions same question and response A & D correct
upvoted 1 times
...
IBB90704
1 month, 2 weeks ago
Selected Answer: AD
When you configure multiple dial-up IPsec VPNs, IKEv2 makes it simpler to match the intended gateway by peer ID. With IKEv2, you can either use the standard peer ID attribute or the Fortinet proprietary network ID attribute to indicate the phase 1 gateway to match on the dial-up server, regardless of the authentication mode in use. However, with IKEv1, you can use the peer ID only, and then combine it with aggressive mode and pre-shared key authentication, or with main mode and certificate signature authentication. Pagina 300 FortiGate_7.4_Administrator_Study_Guide
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...