FCSS_EFW_AD-7.4 · Question #7
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not exposed during VPN establishment. Which protocol can the administrator use to enhance security?
The correct answer is A. Use IKEv2, which encrypts peer IDs and prevents exposure. In ADVPN (Auto-Discovery VPN) configurations, security concerns include protecting peer IDs during VPN establishment. Peer IDs are exchanged in the IKE (Internet Key Exchange) negotiation phase, and their exposure could lead to privacy risks or targeted attacks. IKEv2 encrypts…
Question
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not exposed during VPN establishment. Which protocol can the administrator use to enhance security?
Options
- AUse IKEv2, which encrypts peer IDs and prevents exposure.
- BOpt for SSL VPN web mode because it does not use peer IDs at all.
- CChoose IKEv1 aggressive mode because it simplifies peer identification.
- DStick with IKEv1 main mode because it offers better performance.
How the community answered
(53 responses)- A75% (40)
- B4% (2)
- C6% (3)
- D15% (8)
Explanation
In ADVPN (Auto-Discovery VPN) configurations, security concerns include protecting peer IDs during VPN establishment. Peer IDs are exchanged in the IKE (Internet Key Exchange) negotiation phase, and their exposure could lead to privacy risks or targeted attacks. IKEv2 encrypts peer IDs, making it more secure compared to IKEv1, where peer IDs can be exposed in plaintext in aggressive mode. IKEv2 also provides better performance and flexibility while supporting dynamic tunnel establishment in ADVPN.
Topics
Community Discussion
No community discussion yet for this question.