nse7_efw-72 Exam QuestionsBrowse all questions from this exam

nse7_efw-72 Exam - Question 7


Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

Show Answer
Correct Answer: BC

The IKE version being used is 2, as indicated by 'ver=2'. Both IPsec SAs are loaded on the kernel, as shown by 'npu-flag=00'. Dead peer detection is disabled ('dpd: mode=off'), and forward error correction is also disabled ('fec: egress=0 ingress=0').

Discussion

5 comments
Sign in to comment
5deee77Options: BC
Feb 28, 2024

The answer is B (ver:2) C (npu-flag=00)

havokduOptions: BC
May 26, 2024

ver=2 is IKEv2 dpd: mode=off (dead peer detection is disabled) fec: egreess=0 ingress=0 (forward error correction is disabled) (also FEC is phase1 not 2) npu_flag=00 means that both IPsec SA are loaded in the kernel Study guide page 321

rananajOptions: BC
Feb 22, 2024

The answer is BC

TotoahrenOptions: BD
Mar 18, 2024

BC Response: ver=2 ( this is ikea2) dpd: mode=off (dead peer detection is disabled) fec: egreess=0 ingress=0 (forward error correction is disabled) option c is discard, I'm not sure why

havokdu
May 26, 2024

npu_flag=00 means that both IPsec SA are loaded in the kernel Study guide page 321

charrucoOptions: BC
Apr 24, 2024

B and C are correct