Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCSS_NST_SE-7.6 Exam - Topic 2 Question 8 Discussion

Refer to the exhibit, which contains partial output from an IKE real-time debug.The administrator does not have access to the remote gateway.Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?
A) In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
B) In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
C) In the phase 1 network configuration, set the IKE version to 2.
D) In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.

Fortinet FCSS_NST_SE-7.6 Exam - Topic 2 Question 8 Discussion

Actual exam question for Fortinet's FCSS_NST_SE-7.6 exam
Question #: 8
Topic #: 2
[All FCSS_NST_SE-7.6 Questions]

Refer to the exhibit, which contains partial output from an IKE real-time debug.

The administrator does not have access to the remote gateway.

Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Derrick
3 hours ago
I think option A is the best choice. AES256 is strong.
upvoted 0 times
...
Candra
5 days ago
Surprised no one mentioned B! AESCBC-SHA2 could work too.
upvoted 0 times
...
Natalie
10 days ago
I’m not sure about D. AES128 feels a bit outdated now.
upvoted 0 times
...
Shonda
16 days ago
Wait, why not just go with option C? IKEv2 is more secure.
upvoted 0 times
...
Elise
2 months ago
Definitely agree with A! It’s a strong choice.
upvoted 0 times
...
Lemuel
2 months ago
I think option A is the way to go. AES256 is solid.
upvoted 0 times
...
Ashton
3 months ago
I think adding AES128-SHA128 might be a safe bet since it's a common configuration, but I’m not entirely confident.
upvoted 0 times
...
Malcolm
3 months ago
I feel like I should know this, but I can't recall if IKE version 2 is necessary for this specific scenario.
upvoted 0 times
...
Francesco
3 months ago
This question reminds me of a similar practice one where we had to adjust the encryption settings. I think adding AES256-SHA256 could be the right move.
upvoted 0 times
...
Rochell
3 months ago
I remember we discussed how the encryption algorithms need to match on both ends, but I'm not sure which one is missing here.
upvoted 0 times
...

Save Cancel