Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

An administrator is troubleshooting an IPsec VPN that uses aggressive mode. The VPN establishes successfully, but the administrator is concerned about security. Which statement is true regarding aggressive mode?

⚠ Common exam trap

A common mix-up: candidates confuse aggressive mode's faster negotiation with better security, or mistakenly think the number of messages (three vs. six) implies stronger encryption, when in fact the cleartext identity transmission is the critical security weakness tested on the NSE4 exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Aggressive mode transmits the identification in clear text

In aggressive mode, the IKE phase 1 exchange uses three messages instead of six, and the peer's identity (such as the IP address or FQDN) is transmitted in cleartext during the second message before the secure tunnel is established. This exposes the identity to eavesdropping, making it less secure than main mode, which encrypts the identity after the tunnel is set up. The administrator's concern is valid because aggressive mode sacrifices identity protection for faster negotiation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Aggressive mode is more secure than main mode

    Why it's wrong here

    Aggressive mode is not more secure than main mode; the opposite is true. Main mode uses a six-message exchange that lets both peers establish a Diffie-Hellman shared secret and create an encrypted channel before transmitting their identification payloads, so identities are protected. Aggressive mode sends the identity in the clear, as it has not yet established encryption keys. Thus, main mode is the security-hardened choice when identity privacy is a concern.

  • ✓

    Aggressive mode transmits the identification in clear text

    Why this is correct

    In aggressive mode, the initiator sends its identification (IDi) along with the Diffie-Hellman values in the first packet, and the responder returns its identification (IDr) in the second packet. Because the shared secret is not yet computed when these packets are exchanged, no encryption keys exist, so the ID payloads are transmitted in plaintext. A passive attacker on the network path can capture these packets and directly read the identities of the VPN peers. This is the primary reason aggressive mode is considered insecure for identity protection.

  • ✗

    Aggressive mode provides perfect forward secrecy (PFS) by default

    Why it's wrong here

    Perfect forward secrecy (PFS) is not an inherent attribute of aggressive mode or of any IKE Phase 1 mode; it is an independent configuration in the Phase 2 proposal. PFS forces a new Diffie-Hellman key exchange during each re-key, ensuring that compromising a single long-term key does not expose past session keys. Enabling PFS in the VPN settings is done separately and has no relation to whether main or aggressive mode is selected. Therefore, aggressive mode does not provide PFS by default.

  • ✗

    Aggressive mode uses six messages instead of three

    Why it's wrong here

    Aggressive mode actually requires only three messages to complete IKE Phase 1: the initiator sends its proposal and DH data, the responder answers with the selected proposal and DH data, and the initiator confirms. This compact exchange reduces the number of round trips and makes aggressive mode faster, but it sacrifices identity protection because the identities are exposed in those early packets. The six-message exchange is characteristic of main mode, which separates the negotiation into a cryptographic proposal phase and an authenticated key exchange phase.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.