exam questions

Exam FCSS_NST_SE-7.4 All Questions

View all questions & answers for the FCSS_NST_SE-7.4 exam

Exam FCSS_NST_SE-7.4 topic 1 question 10 discussion

Actual exam question from Fortinet's FCSS_NST_SE-7.4
Question #: 10
Topic #: 1
[All FCSS_NST_SE-7.4 Questions]

Refer to the exhibit, which contains the partial configuration of an IPsec VPN configuration.

After reviewing the configuration, what can you conclude about the IPsec VPN Phase 1 setup?

  • A. The VPN is configured using IKEv2.
  • B. Dead Peer Detection is disabled.
  • C. The VPN is configured with DHCP over IPsec.
  • D. The tunnel is configured as a route-based VPN.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
payafs
Highly Voted 3 months, 2 weeks ago
Selected Answer: C
set type dynamic and set ipv4-start-ip and set ipv4-end-ip These settings indicate that the VPN is set up to support remote dial-up clients that dynamically receive configuration information
upvoted 5 times
...
sxcap
Most Recent 12 hours ago
Selected Answer: C
- The use of set type dynamic and lack of set local-gw or set remote-gw tied to interfaces indicates this is a policy-based VPN, not route-based.
upvoted 1 times
...
Schlumpy
1 week, 2 days ago
Selected Answer: C
It cant be D because the set type is dynamic.
upvoted 1 times
...
cgallardo
2 months ago
Selected Answer: D
DHCP over IPSEC is achieve in phase2 with the setting: set dhcp-ipsec enable
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...