nerdexam
Juniper

JN0-632 · Question #158

Click the Exhibit button. The exhibit shows an IPSec tunnel configuration. In an effort to increase the security of the tunnel, you must configure the tunnel to negotiate a new tunnel key during IKE…

The correct answer is C. PFS must be added to the IPSec policy poi-IPSec. See the full explanation below for the reasoning.

Question

Click the Exhibit button. The exhibit shows an IPSec tunnel configuration. In an effort to increase the security of the tunnel, you must configure the tunnel to negotiate a new tunnel key during IKE phase 2. How can the configuration be changed to accommodate this requirement?

Exhibit

JN0-632 question #158 exhibit

Options

  • AA new tunnel key is negotiated by default during phase 2; no configuration change is necessary.
  • BPFS must be added to the IKE policy pol-ike.
  • CPFS must be added to the IPSec policy poi-IPSec.
  • DA new tunnel key cannot be negotiated in IKE phase 2 with route-based IPSec VPNs; a policy- based

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    71% (12)
  • D
    18% (3)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice