nerdexam
Juniper

JN0-632 · Question #49

Click the Exhibit button. A junior member of the network team has set up a new VPN tunnel using a PKI certificate and is unable to establish the tunnel. After troubleshooting the problem and…

The correct answer is D. There is no trusted CA configured, which is required for PKI-based tunnels. See the full explanation below for the reasoning.

Question

Click the Exhibit button. A junior member of the network team has set up a new VPN tunnel using a PKI certificate and is unable to establish the tunnel. After troubleshooting the problem and confirming that the proposals and encryption algorithms match on both sides, they ask you for help. Referring to the exhibit, what is the cause of this problem? Juniper JN0-632 Exam

Exhibit

JN0-632 question #49 exhibit

Options

  • AThe authentication method must be changed to pre-shared-keys to make use of the PKI certificate
  • BThe proposal set is missing which will cause the VPN tunnel to not establish.
  • CPKI-based VPN tunnels cannot use main mode; aggressive mode must be used.
  • DThere is no trusted CA configured, which is required for PKI-based tunnels.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    4% (1)
  • D
    83% (20)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice