NSE4 Authentication and VPN Practice Question
An administrator is troubleshooting an IPsec VPN that uses aggressive mode. The VPN establishes successfully, but the administrator is concerned about security. Which statement is true regarding aggressive mode?
⚠ Common exam trap
A common mix-up: candidates confuse aggressive mode's faster negotiation with better security, or mistakenly think the number of messages (three vs. six) implies stronger encryption, when in fact the cleartext identity transmission is the critical security weakness tested on the NSE4 exam.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Aggressive mode transmits the identification in clear text
In aggressive mode, the IKE phase 1 exchange uses three messages instead of six, and the peer's identity (such as the IP address or FQDN) is transmitted in cleartext during the second message before the secure tunnel is established. This exposes the identity to eavesdropping, making it less secure than main mode, which encrypts the identity after the tunnel is set up. The administrator's concern is valid because aggressive mode sacrifices identity protection for faster negotiation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Aggressive mode is more secure than main mode
Why it's wrong here
Aggressive mode is not more secure than main mode; the opposite is true. Main mode uses a six-message exchange that lets both peers establish a Diffie-Hellman shared secret and create an encrypted channel before transmitting their identification payloads, so identities are protected. Aggressive mode sends the identity in the clear, as it has not yet established encryption keys. Thus, main mode is the security-hardened choice when identity privacy is a concern.
- ✓
Aggressive mode transmits the identification in clear text
Why this is correct
In aggressive mode, the initiator sends its identification (IDi) along with the Diffie-Hellman values in the first packet, and the responder returns its identification (IDr) in the second packet. Because the shared secret is not yet computed when these packets are exchanged, no encryption keys exist, so the ID payloads are transmitted in plaintext. A passive attacker on the network path can capture these packets and directly read the identities of the VPN peers. This is the primary reason aggressive mode is considered insecure for identity protection.
- ✗
Aggressive mode provides perfect forward secrecy (PFS) by default
Why it's wrong here
Perfect forward secrecy (PFS) is not an inherent attribute of aggressive mode or of any IKE Phase 1 mode; it is an independent configuration in the Phase 2 proposal. PFS forces a new Diffie-Hellman key exchange during each re-key, ensuring that compromising a single long-term key does not expose past session keys. Enabling PFS in the VPN settings is done separately and has no relation to whether main or aggressive mode is selected. Therefore, aggressive mode does not provide PFS by default.
- ✗
Aggressive mode uses six messages instead of three
Why it's wrong here
Aggressive mode actually requires only three messages to complete IKE Phase 1: the initiator sends its proposal and DH data, the responder answers with the selected proposal and DH data, and the initiator confirms. This compact exchange reduces the number of round trips and makes aggressive mode faster, but it sacrifices identity protection because the identities are exposed in those early packets. The six-message exchange is characteristic of main mode, which separates the negotiation into a cryptographic proposal phase and an authenticated key exchange phase.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.