Fortinet Fortianalyzer Analyst FCP Fortianalyzer 74 · Free Practice Question Medium

Question 4

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

  • A

    A. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.

  • B

    B. Must establish an IPsec tunnel ID and pre-shared key.

  • C

    C. IPsec cannot be enabled if SSL is enabled as well. 

  • D

    D. IPsec is only enabled through the CLI on FortiAnalyzer.

Reveal correct answers

Correct answers: B, D

Explanation

The correct answers are:

B. Must establish an IPsec tunnel ID and pre-shared key.

D. IPsec is only enabled through the CLI on FortiAnalyzer.


Explanation:

B. Must establish an IPsec tunnel ID and pre-shared key: To secure communications between FortiAnalyzer and FortiGate with IPsec, you need to establish an IPsec tunnel ID and a pre-shared key. This ensures that both ends of the tunnel can authenticate and establish a secure connection.

D. IPsec is only enabled through the CLI on FortiAnalyzer: Enabling IPsec on FortiAnalyzer is done through the command-line interface (CLI). This requires specific commands to configure the IPsec settings and establish the secure tunnel.

The other options are incorrect:

  • A. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated: Both ends of the IPsec tunnel (FortiAnalyzer and FortiGate) must be configured. The FortiGate end is not auto-negotiated.

  • C. IPsec cannot be enabled if SSL is enabled as well: IPsec can be enabled even if SSL is enabled. They are separate protocols and can be configured independently.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need