Implementing and Operating Cisco Security Core Technologies v1.1 (350-701 SCOR v1.1) Exam Materials-Question 313 Discussion
Comment Image Comment Image Comment Image

Refer to the exhibit. An engineer is implementing a certificate based VPN. What is the result of the existing configuration? (Choose one answer)

  • A. Only an IKEv2 peer that has an OU certificate attribute set to MANGLER establishes an IKEv2 SA successfully.
  • B. The OU of the IKEv2 peer certificate is encrypted when the OU is set to MANGLER.
  • C. The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.
  • D. The OU of the IKEv2 peer certificate is set to MANGLER.
Correct Answer: C

Brave-Dump Clients Votes

C 100%

Comments



Brave-Dumps.com Admin 2026-07-26 00:33:29

Selected Answers: C


The match identity certificate command in an IKEv2 authorization policy specifies which certificate attribute should be used to match the peer against the policy. In this case, the policy checks the Organizational Unit (OU) field and expects its value to be MANGLER.

Therefore, when an IKEv2 peer presents a certificate whose OU attribute is set to MANGLER, the router uses that value to evaluate the authorization policy. If the certificate identity matches the policy criteria, the IKEv2 security association can be established successfully.