FCP_FGT_AD-7.4 · Question #37
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)
The correct answer is A. Pre-shared key and certificate signature as authentication methods B. Extended authentication (XAuth) to request the remote peer to provide a username and password. FortiGate supports both pre-shared key and certificate signature methods for IKEv1 authentication. These methods provide flexibility depending on the security requirements of the network. Additionally, FortiGate supports Extended Authentication (XAuth), which requests a…
Question
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)
Options
- APre-shared key and certificate signature as authentication methods
- BExtended authentication (XAuth) to request the remote peer to provide a username and password
- CExtended authentication (XAuth) for faster authentication because fewer packets are exchanged
- DNo certificate is required on the remote peer when you set the certificate signature as the
How the community answered
(28 responses)- A82% (23)
- C14% (4)
- D4% (1)
Explanation
FortiGate supports both pre-shared key and certificate signature methods for IKEv1 authentication. These methods provide flexibility depending on the security requirements of the network. Additionally, FortiGate supports Extended Authentication (XAuth), which requests a username and password from the remote peer, enhancing security by adding an extra layer of authentication. The XAuth method does not necessarily make the authentication faster; it is an additional security measure.
Topics
Community Discussion
No community discussion yet for this question.