CCSM Advanced VPN Troubleshooting Practice Question
A Check Point Security Gateway is configured for a site-to-site VPN with a Cisco ASA. The tunnel is up, but traffic is not passing. You suspect a Phase 2 issue. Which TWO of the following should you check to resolve the problem? (Choose two.)
⚠ Common exam trap
The trap here is assuming that Phase 1 settings like shared secret or certificates are still relevant even though the tunnel is up, which indicates Phase 1 is functioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the encryption domains on both gateways are symmetrical and include all necessary subnets.
The two critical checks for Phase 2 traffic issues are the encryption domains and the Phase 2 proposal. If the encryption domains are not symmetrical or are missing subnets, traffic will not be encrypted or accepted. If the Phase 2 proposal algorithms do not match, the IPsec SA cannot be established or will fail to process traffic. Both are common causes of traffic failure despite an active tunnel. Phase 1 settings like shared secret or certificates are not relevant because the tunnel is already up.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the encryption domains on both gateways are symmetrical and include all necessary subnets.
Why this is correct
Encryption domains define which traffic is protected by the VPN. If the domains are not symmetrical or are missing subnets, traffic from those subnets will not be encrypted or accepted. This is a common cause of Phase 2 traffic failures. Ensuring both gateways have matching encryption domains that include all relevant subnets is essential for proper VPN operation.
- ✓
Ensure that the Phase 2 proposal (encryption and integrity algorithms) matches on both gateways.
Why this is correct
The Phase 2 proposal must match for the IPsec SA to be established. If the encryption or integrity algorithms differ, the gateways cannot agree on a proposal, leading to Phase 2 failure. Even if the tunnel is up, a mismatch can cause traffic to be dropped or not encrypted properly. Verifying that both peers support at least one common algorithm set is crucial.
- ✗
Check that the IKE Phase 1 shared secret matches on both gateways.
Why it's wrong here
The shared secret is used in Phase 1 for authentication. If it were incorrect, Phase 1 would fail, and the tunnel would not be up. Since the tunnel is up, Phase 1 is successful, so the shared secret is not the issue. Checking it would not resolve the Phase 2 traffic problem.
- ✗
Verify that the peer gateway's certificate is valid and not expired.
Why it's wrong here
Certificate validity is part of Phase 1 authentication. If the certificate were expired, Phase 1 would fail, and the tunnel would not be up. Since the tunnel is up, the certificate is valid. Therefore, checking it is not relevant to the Phase 2 traffic issue.
- ✗
Check that the IKE Phase 1 lifetime matches on both gateways.
Why it's wrong here
The Phase 1 lifetime determines how long the Phase 1 SA remains valid before renegotiation. A mismatch in lifetimes typically does not prevent traffic from passing; it may cause renegotiation at different times, but the tunnel would still function. Since the tunnel is up and traffic is not passing, the issue is more likely related to Phase 2 parameters or encryption domains.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.