Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

A Check Point Security Gateway is configured for a site-to-site VPN with a Cisco ASA. The tunnel is up, but traffic is not passing. You suspect a Phase 2 issue. Which TWO of the following should you check to resolve the problem? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Phase 1 settings like shared secret or certificates are still relevant even though the tunnel is up, which indicates Phase 1 is functioning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the encryption domains on both gateways are symmetrical and include all necessary subnets.

The two critical checks for Phase 2 traffic issues are the encryption domains and the Phase 2 proposal. If the encryption domains are not symmetrical or are missing subnets, traffic will not be encrypted or accepted. If the Phase 2 proposal algorithms do not match, the IPsec SA cannot be established or will fail to process traffic. Both are common causes of traffic failure despite an active tunnel. Phase 1 settings like shared secret or certificates are not relevant because the tunnel is already up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify that the encryption domains on both gateways are symmetrical and include all necessary subnets.

    Why this is correct

    Encryption domains define which traffic is protected by the VPN. If the domains are not symmetrical or are missing subnets, traffic from those subnets will not be encrypted or accepted. This is a common cause of Phase 2 traffic failures. Ensuring both gateways have matching encryption domains that include all relevant subnets is essential for proper VPN operation.

  • ✓

    Ensure that the Phase 2 proposal (encryption and integrity algorithms) matches on both gateways.

    Why this is correct

    The Phase 2 proposal must match for the IPsec SA to be established. If the encryption or integrity algorithms differ, the gateways cannot agree on a proposal, leading to Phase 2 failure. Even if the tunnel is up, a mismatch can cause traffic to be dropped or not encrypted properly. Verifying that both peers support at least one common algorithm set is crucial.

  • ✗

    Check that the IKE Phase 1 shared secret matches on both gateways.

    Why it's wrong here

    The shared secret is used in Phase 1 for authentication. If it were incorrect, Phase 1 would fail, and the tunnel would not be up. Since the tunnel is up, Phase 1 is successful, so the shared secret is not the issue. Checking it would not resolve the Phase 2 traffic problem.

  • ✗

    Verify that the peer gateway's certificate is valid and not expired.

    Why it's wrong here

    Certificate validity is part of Phase 1 authentication. If the certificate were expired, Phase 1 would fail, and the tunnel would not be up. Since the tunnel is up, the certificate is valid. Therefore, checking it is not relevant to the Phase 2 traffic issue.

  • ✗

    Check that the IKE Phase 1 lifetime matches on both gateways.

    Why it's wrong here

    The Phase 1 lifetime determines how long the Phase 1 SA remains valid before renegotiation. A mismatch in lifetimes typically does not prevent traffic from passing; it may cause renegotiation at different times, but the tunnel would still function. Since the tunnel is up and traffic is not passing, the issue is more likely related to Phase 2 parameters or encryption domains.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.