Fortinet
NSE7_SDW-7.2 · Question #36
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )
The correct answer is B. XAuth is enabled as an additional level of authentication, which requires a username and C. A total of six packets are exchanged between an initiator and a responder instead of three. See the full explanation below for the reasoning.
Question
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )
Options
- AA peer ID is included in the first packet from the initiator, along with suggested security policies.
- BXAuth is enabled as an additional level of authentication, which requires a username and
- CA total of six packets are exchanged between an initiator and a responder instead of three
- DThe use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
How the community answered
(38 responses)- A11% (4)
- B84% (32)
- D5% (2)
Community Discussion
No community discussion yet for this question.