Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium
Question 2
Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)
-
A
A. No certificate is required on the remote peer when you set the certificate signature as the authentication method
-
B
B. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged
-
C
C. Extended authentication (XAuth)to request the remote peer to provide a username and password
-
D
D. Pre-shared key and certificate signature as authentication methods
Reveal correct answers
Correct answers: C, D
Explanation
C. Extended authentication (XAuth) to request the remote peer to provide a username and password
D. Pre-shared key and certificate signature as authentication methods
Explanation:
(C) Correct - XAuth for User Authentication
FortiGate supports Extended Authentication (XAuth) in IKEv1.
XAuth allows FortiGate to request a username and password from the remote peer for an additional layer of authentication.
(D) Correct - Supported Authentication Methods
FortiGate supports both pre-shared keys (PSK) and certificate-based authentication in IKEv1 for IPsec VPNs.
Why the Other Options Are Incorrect?
(A) No certificate is required on the remote peer when you set the certificate signature as the authentication method (Incorrect)
If certificate-based authentication is used, both peers must have certificates (either self-signed or from a CA).
(B) Extended authentication (XAuth) for faster authentication because fewer packets are exchanged (Incorrect)
XAuth actually adds an additional authentication step, which increases the number of packets exchanged, not reduces them.
Conclusion:
FortiGate supports XAuth for user authentication and both PSK and certificate-based authentication for IKEv1 IPsec VPNs.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
