View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam
Question 1 Discussion
Comments
Selected Answers: B, D
Selected Answers: B, D
C is wrong because it requires at least 2 exchanges (IKE_SA_INIT and IKE_AUTH), and each of these exchanges has 2 messages (request and response), so 4 messages in total. Additional exchanges are (Create_Child_SA & Information Exchange), considering first Child SA is included in second exchange IKE_AUTH.
B should actually be wrong, as both IKEv1 and IKEv2 support same DH groups despite what is mentioned in Study Guide. Seems to be outdated info when ECC DH Groups were supported only in IKEv2.
What do you think?
If you implement IKEv2 in a VPN topology, which two statements are true? (Choose two answers)
Brave-Dump Clients Votes