Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

Which option is recommended to prevent 'VPN tunnel flapping' when a connection is unstable?

⚠ Common exam trap

Candidates often suggest increasing tunnel timeouts or rekeying intervals, which does not address the underlying issue of an unstable connection that requires DPD to detect and handle peer loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configuring appropriate Dead Peer Detection (DPD) settings.

VPN tunnel flapping often occurs when the connection is intermittently lost, causing the gateway to constantly attempt to renegotiate the tunnel. Configuring a proper rekeying interval and, more importantly, setting up reliable Dead Peer Detection (DPD) helps manage state transitions gracefully. By properly tuning these timers, the administrator ensures that the gateway does not tear down and rebuild tunnels unnecessarily, maintaining a more stable connection during minor packet loss events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increasing the IKE Phase 1 lifetime to infinity.

    Why it's wrong here

    Setting a lifetime to infinity is a major security risk, as it prevents the regular rotation of encryption keys. If keys are never rotated, an attacker has a much larger window to perform cryptographic analysis and potentially compromise the tunnel's secrecy over time.

  • ✗

    Disabling IKE Phase 2 rekeying entirely.

    Why it's wrong here

    Disabling rekeying is dangerous because keys are intended to be rotated periodically to ensure forward secrecy. Without rekeying, the tunnel remains vulnerable to cryptanalysis, and the gateway will eventually stop processing traffic once the security association expires, leading to a permanent tunnel outage.

  • ✓

    Configuring appropriate Dead Peer Detection (DPD) settings.

    Why this is correct

    DPD allows the gateway to verify the health of the tunnel peer actively. By tuning the DPD interval and timeout, administrators can make the tunnel more resilient to transient network glitches, preventing unnecessary tear-downs and ensuring that flapping is minimized during periods of minor instability.

  • ✗

    Using only MD5 for IKE phase 2 authentication.

    Why it's wrong here

    MD5 is considered cryptographically insecure by modern standards. Using it provides no benefit for tunnel stability and significantly weakens the overall security posture of the VPN. Administrators should always prefer SHA-256 or stronger algorithms for both authentication and integrity checks to ensure robust protection.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.