Fortinet Fortianalyzer Analyst FCP Fortianalyzer 74 · Free Practice Question Medium
Question 4
Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)
-
A
A. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
-
B
B. Must establish an IPsec tunnel ID and pre-shared key.
-
C
C. IPsec cannot be enabled if SSL is enabled as well.
-
D
D. IPsec is only enabled through the CLI on FortiAnalyzer.
Reveal correct answers
Correct answers: B, D
Explanation
The correct answers are:
B. Must establish an IPsec tunnel ID and pre-shared key.
D. IPsec is only enabled through the CLI on FortiAnalyzer.
Explanation:
B. Must establish an IPsec tunnel ID and pre-shared key: To secure communications between FortiAnalyzer and FortiGate with IPsec, you need to establish an IPsec tunnel ID and a pre-shared key. This ensures that both ends of the tunnel can authenticate and establish a secure connection.
D. IPsec is only enabled through the CLI on FortiAnalyzer: Enabling IPsec on FortiAnalyzer is done through the command-line interface (CLI). This requires specific commands to configure the IPsec settings and establish the secure tunnel.
The other options are incorrect:
A. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated: Both ends of the IPsec tunnel (FortiAnalyzer and FortiGate) must be configured. The FortiGate end is not auto-negotiated.
C. IPsec cannot be enabled if SSL is enabled as well: IPsec can be enabled even if SSL is enabled. They are separate protocols and can be configured independently.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
