Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

Which IKE Phase 2 proposal setting specifically ensures that session keys are not derived from the original long-term keys, protecting past sessions if a key is compromised?

⚠ Common exam trap

Candidates often confuse Phase 1 aggressive/main mode parameters with Phase 2 key derivation properties, forgetting that Perfect Forward Secrecy specifically protects past sessions using unique key exchanges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perfect Forward Secrecy (PFS)

Perfect Forward Secrecy (PFS) is a property of key-agreement protocols that ensures a session key derived from a set of long-term keys will not be compromised if one of the long-term keys is compromised in the future. By forcing a new Diffie-Hellman exchange during Phase 2, the gateway ensures each session has unique, independent keying material, which is a best practice for high-security environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Main Mode

    Why it's wrong here

    Main Mode is an IKE Phase 1 negotiation mode that provides identity protection by encrypting the exchange. It does not provide forward secrecy for the data traffic SAs, as it only handles the initial authentication and setup of the management tunnel.

  • ✓

    Perfect Forward Secrecy (PFS)

    Why this is correct

    PFS triggers a new Diffie-Hellman key exchange during the Quick Mode (Phase 2) negotiation. This ensures that the keys used for encrypting the data traffic are mathematically independent of the initial master keys used for the tunnel, providing the required forward security.

  • ✗

    Aggressive Mode

    Why it's wrong here

    Aggressive mode is a faster negotiation method that does not protect the identity of the peers as effectively as Main Mode. It does not have any relationship with session key derivation or the forward security of the encrypted data packets.

  • ✗

    Anti-Replay Protection

    Why it's wrong here

    Anti-Replay is a security mechanism that prevents attackers from capturing and re-sending encrypted packets to disrupt the session. While it is a critical IPsec feature, it is unrelated to key derivation or the mathematical property of forward secrecy.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.