NSE7_SDW-6.4 Exam QuestionsBrowse all questions from this exam

NSE7_SDW-6.4 Exam - Question 38


Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)

Show Answer
Correct Answer: AC

In main mode, the peer ID is not included in the initial exchange of packets, whereas in aggressive mode, the peer ID is included in the first packet from the initiator along with suggested security policies, allowing for a quicker negotiation but with less security. Additionally, aggressive mode uses only three packets in the negotiation process between an initiator and responder, whereas main mode uses six packets, making it more secure but slower.

Discussion

10 comments
Sign in to comment
Max_71Options: BC
Sep 26, 2022

Peer ID is sent only in aggressive mode correct answer B C

evdwOptions: AC
Sep 4, 2022

Agree correct answer is A,C

BoardPanda
Sep 25, 2022

Answer is correct, but question should read "how is aggressive mode different from main mode"

Ernestokoro
Oct 10, 2022

correct ans is BC

aidnetOptions: AC
Oct 21, 2022

correct

josemblitoOptions: AC
Oct 23, 2022

AAuth is phase 1.5

Bob_OsoOptions: AC
Nov 12, 2022

AC refer to SD-WAN_6.4_Study_Guide page 177

neoravenOptions: AC
Nov 28, 2022

AC corrects

TcmhOptions: AC
Jul 20, 2023

Answer is A, C https://community.fortinet.com/t5/FortiGate/Technical-Tip-Differences-between-Aggressive-and-Main-mode-in/ta-p/196313

DiiLANOptions: AC
Apr 24, 2024

correct