exam questions

Exam NSE7_SDW-6.4 All Questions

View all questions & answers for the NSE7_SDW-6.4 exam

Exam NSE7_SDW-6.4 topic 1 question 25 discussion

Actual exam question from Fortinet's NSE7_SDW-6.4
Question #: 25
Topic #: 1
[All NSE7_SDW-6.4 Questions]

Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)

  • A. A peer ID is included in the first packet from the initiator, along with suggested security policies.
  • B. XAuth is enabled as an additional level of authentication, which requires a username and password.
  • C. A total of six packets are exchanged between an initiator and a responder instead of three packets.
  • D. The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jack987
1 year, 7 months ago
Selected Answer: AC
Refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Differences-between-Aggressive-and-Main-mode-in/ta-p/196313
upvoted 1 times
...
Andres21216
1 year, 11 months ago
I believe it is B and C by process of elimination. Since A is a characteristic of aggressive mode and that is not the question, and D is not mentioned in the curriculum. C is definitely a valid difference, but B is the only one left, even though it is a configurable feature in both modes.
upvoted 1 times
...
neoraven
2 years, 5 months ago
Selected Answer: AC
A and C
upvoted 2 times
...
neoraven
2 years, 5 months ago
A and C are correct Peer ID is included in the initiating packet - Aggressive Mode // in Main mode is included in the packet 5. Main mode 6 packets // Aggresive mode only three what b says is correct but it is not a difference between the two modes, you can enable Xauth in both modes, is a phase 1.5. Page 177-178
upvoted 3 times
...
Bob_Oso
2 years, 5 months ago
Selected Answer: AC
AC refer to SD-WAN_6.4_Study_Guide page 177-178
upvoted 2 times
...
aidnet
2 years, 6 months ago
Selected Answer: AC
CORRECT
upvoted 1 times
...
josemblito
2 years, 6 months ago
Selected Answer: AC
XAuth happens after phase 1 is UP.. pag 179 A: Peer ID and C: 6 packets are correct.
upvoted 1 times
...
Ernestokoro
2 years, 7 months ago
But peer ID is included on both Main and Aggressive mode. MM= Peer ID + Main Mode + Certificate Signature AM= Peer ID+ Aggressive Mode + PSK This infor is from SDWAN Slide on fortinet site. So correct ans is BC
upvoted 1 times
josemblito
2 years, 6 months ago
XAuth happens after phase 1 is UP.. pag 179 A: Peer ID and C: 6 packets are correct.
upvoted 1 times
...
...
haphap
2 years, 7 months ago
the correct answer is A C. XAuth is enabled is known as phase 1.5
upvoted 1 times
...
Max_71
2 years, 7 months ago
Selected Answer: BC
This peer ID This option is available when Aggressive Mode is enabled. Enter the identifier that is used to authenticate the remote peer. This identifier must match the Local ID that the remote peer’s administrator has configured.
upvoted 2 times
...
BoardPanda
2 years, 7 months ago
B and C is correct. AGRESSIVE mode sends a peer ID in the first packet.
upvoted 4 times
...
eww_cybr
2 years, 7 months ago
A,C SD-WAN 6.4.5 Study Guide. pg 177-178
upvoted 4 times
...
evdw
2 years, 8 months ago
I think that correct answer is A,C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago