NSE4 · Question #98
What is IPsec Perfect Forwarding Secrecy (PFS)?.
The correct answer is B. A phase-2 setting that allows the recalculation of a new common secret key each time the. This question asks for the definition of Perfect Forward Secrecy (PFS) in the context of IPsec.
Question
What is IPsec Perfect Forwarding Secrecy (PFS)?.
Options
- AA phase-1 setting that allows the use of symmetric encryption.
- BA phase-2 setting that allows the recalculation of a new common secret key each time the
- CA `key-agreement' protocol.
- DA `security-association-agreement' protocol.
How the community answered
(59 responses)- A5% (3)
- B90% (53)
- C3% (2)
- D2% (1)
Why each option
This question asks for the definition of Perfect Forward Secrecy (PFS) in the context of IPsec.
Symmetric encryption is a core component of both Phase 1 and Phase 2, but PFS is a specific setting within Phase 2 related to key generation, not a broad allowance for symmetric encryption in Phase 1.
Perfect Forward Secrecy (PFS) is a Phase 2 setting that ensures a compromise of one session key does not compromise past or future session keys by forcing a new Diffie-Hellman key exchange for each new Phase 2 security association.
PFS is not a key-agreement protocol itself; rather, it leverages key-agreement protocols (like Diffie-Hellman) within Phase 2 to achieve forward secrecy.
PFS is a security feature configured within the security association (SA) agreement process, not an agreement protocol itself.
Concept tested: IPsec Perfect Forward Secrecy (PFS)
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/603173/phase-1-settings#Perfect_Forward_Secrecy
Topics
Community Discussion
No community discussion yet for this question.