Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)
Refer to the exhibit, which contains information about an IPsec VPN tunnel.
What two conclusions can you draw from the command output? (Choose two.)
The IKE version being used is 2, as indicated by 'ver=2'. Both IPsec SAs are loaded on the kernel, as shown by 'npu-flag=00'. Dead peer detection is disabled ('dpd: mode=off'), and forward error correction is also disabled ('fec: egress=0 ingress=0').
The answer is B (ver:2) C (npu-flag=00)
ver=2 is IKEv2 dpd: mode=off (dead peer detection is disabled) fec: egreess=0 ingress=0 (forward error correction is disabled) (also FEC is phase1 not 2) npu_flag=00 means that both IPsec SA are loaded in the kernel Study guide page 321
The answer is BC
BC Response: ver=2 ( this is ikea2) dpd: mode=off (dead peer detection is disabled) fec: egreess=0 ingress=0 (forward error correction is disabled) option c is discard, I'm not sure why
npu_flag=00 means that both IPsec SA are loaded in the kernel Study guide page 321
B and C are correct