nerdexam
Fortinet

NSE7_SDW-7.2 · Question #36

Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )

The correct answer is B. XAuth is enabled as an additional level of authentication, which requires a username and C. A total of six packets are exchanged between an initiator and a responder instead of three. See the full explanation below for the reasoning.

Question

Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )

Options

  • AA peer ID is included in the first packet from the initiator, along with suggested security policies.
  • BXAuth is enabled as an additional level of authentication, which requires a username and
  • CA total of six packets are exchanged between an initiator and a responder instead of three
  • DThe use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    84% (32)
  • D
    5% (2)

Community Discussion

No community discussion yet for this question.

Full NSE7_SDW-7.2 Practice