Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

Which TWO of the following are common reasons for VPN tunnel packet fragmentation?

⚠ Common exam trap

Candidates mistakenly attribute fragmentation solely to MTU mismatches without considering the impact of cryptographic encapsulation overhead and MSS configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN overhead exceeding the path MTU

Fragmentation occurs when the packet size, combined with the additional overhead of VPN headers (like ESP), exceeds the Maximum Transmission Unit (MTU) of the path between gateways. This is a common performance killer in VPNs. It can be mitigated by reducing the MSS value in the TCP settings or by adjusting the interface MTU, ensuring packets do not need to be split and reassembled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPN overhead exceeding the path MTU

    Why this is correct

    VPN encapsulation (ESP/AH) adds bytes to the original packet. If the total size exceeds the MTU of the path, intermediate routers will fragment the packet. This increases CPU usage on the receiving gateway, which must reassemble the fragments before it can decrypt the encapsulated VPN traffic.

  • ✓

    Mismatched MSS (Maximum Segment Size) values

    Why this is correct

    If the internal hosts are sending packets with an MSS that doesn't account for VPN overhead, the packets will be too large. Adjusting the MSS on the gateway ensures the TCP three-way handshake negotiates smaller packets, preventing fragmentation before it happens at the IP layer for TCP traffic.

  • ✗

    Incorrect IKE Phase 2 encryption algorithm

    Why it's wrong here

    The encryption algorithm selected, such as AES-GCM or AES-CBC, does not directly cause packet fragmentation. While different algorithms might have slightly different padding requirements, the fundamental cause of fragmentation is the packet size relative to the MTU, not the choice of the encryption cipher itself.

  • ✗

    Expired IPsec security associations

    Why it's wrong here

    An expired security association (SA) will result in dropped traffic, not packet fragmentation. When an SA expires, the gateway simply ceases to have the cryptographic keys to process the traffic, causing a complete failure to transport data rather than a performance issue related to packet sizing.

  • ✗

    High CPU utilization on the gateway

    Why it's wrong here

    High CPU utilization is a symptom of poor performance, not a cause of packet fragmentation. While fragmentation does increase CPU load due to the reassembly process, the CPU load itself does not dictate the size of the packets passing through the VPN tunnel or the network path.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.