nerdexam
Juniper

JN0-632 · Question #158

JN0-632 Question #158: Real Exam Question with Answer & Explanation

Sign in or unlock JN0-632 to reveal the answer and full explanation for question #158. The question stem and answer options stay visible for context.

Question

Click the Exhibit button. The exhibit shows an IPSec tunnel configuration. In an effort to increase the security of the tunnel, you must configure the tunnel to negotiate a new tunnel key during IKE phase 2. How can the configuration be changed to accommodate this requirement?

Exhibit

JN0-632 question #158 exhibit

Options

  • AA new tunnel key is negotiated by default during phase 2; no configuration change is necessary.
  • BPFS must be added to the IKE policy pol-ike.
  • CPFS must be added to the IPSec policy poi-IPSec.
  • DA new tunnel key cannot be negotiated in IKE phase 2 with route-based IPSec VPNs; a policy- based

Unlock JN0-632 to see the answer

You've previewed enough free JN0-632 questions. Unlock JN0-632 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full JN0-632 Practice