NSE4 · Question #433
Which of the following IKE modes is the one used during the IPsec phase 2 negotiation?
The correct answer is B. Quick mode. This question identifies the specific IKE mode used during the second phase of an IPsec VPN negotiation.
Question
Which of the following IKE modes is the one used during the IPsec phase 2 negotiation?
Options
- AAggressive mode
- BQuick mode
- CMain mode
- DFast mode
How the community answered
(53 responses)- A6% (3)
- B91% (48)
- C2% (1)
- D2% (1)
Why each option
This question identifies the specific IKE mode used during the second phase of an IPsec VPN negotiation.
Aggressive mode is an IKE Phase 1 negotiation mode, used to establish the initial secure tunnel for key exchange, not for Phase 2 data protection.
Quick mode is the IKE mode exclusively used during IPsec Phase 2 negotiation to establish the IPsec Security Association (SA) for protecting the actual data traffic, relying on the secure tunnel established in Phase 1.
Main mode is an IKE Phase 1 negotiation mode, used to establish the initial secure tunnel for key exchange, offering higher security than aggressive mode but also not for Phase 2.
Fast mode is not a standard, recognized IKE negotiation mode; it is sometimes confused with Quick Mode or used colloquially.
Concept tested: IPsec IKE negotiation phases
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/20967/vpn-concepts
Topics
Community Discussion
No community discussion yet for this question.