Courseiva
Authentication and VPN →easyMultiple Choice

NSE4 Authentication and VPN Practice Question

Which IPsec VPN mode uses IP addresses and ports to define interesting traffic, and requires a separate security policy for each tunnel?

⚠ Common exam trap

A common mix-up: candidates confuse 'policy-based VPN' with 'route-based VPN', mistakenly thinking that route-based VPNs require separate security policies per tunnel, when in fact route-based VPNs use a single policy tied to the IPsec interface and leverage routing to handle multiple destinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Policy-based VPN

Policy-based VPN (B) is correct because it defines interesting traffic using source/destination IP addresses and ports, and each tunnel requires a separate security policy to specify which traffic should be encrypted. This contrasts with route-based VPNs, which use virtual interfaces and routing tables to determine traffic, allowing a single policy to handle multiple tunnels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hub-and-spoke VPN

    Why it's wrong here

    Hub-and-spoke VPN describes a common topology in which multiple remote sites connect to a central hub, but it is not an IPsec mode that selects traffic by IP addresses and ports. Traffic selection in a hub-and-spoke deployment still depends on either policy-based or route-based configuration. Therefore, it cannot be the correct answer to a question about traffic-defining modes.

  • ✓

    Policy-based VPN

    Why this is correct

    Policy-based VPN is the correct IPsec mode because it uses firewall policies to define interesting traffic by matching source/destination IP addresses, protocols, and ports, and then applies action 'IPsec' to encrypt that traffic. In FortiGate, the policy also references the IPsec phase1/phase2 VPN tunnel and security profiles, making the policy the single point of traffic selection. This is exactly how addresses and ports determine which traffic goes over the VPN.

  • ✗

    Dial-up VPN

    Why it's wrong here

    Dial-up VPN refers to a scenario where remote clients initiate a VPN connection on demand, often receiving dynamic IP addresses from the FortiGate via mode-config, rather than a mode that defines interesting traffic by IP and port. While dial-up deployments may use firewall policies for traffic matching, the term itself describes the client-initiated call setup and tunnel negotiation, not the address/port-based traffic selection mechanism. Thus it is not the mode asked about.

  • ✗

    Route-based VPN

    Why it's wrong here

    Route-based VPN is a mode that establishes an IPsec tunnel interface and selects interesting traffic through the routing table and source/destination routes, not by matching addresses and ports in a firewall policy. Because the tunnel behaves as an overlay network interface, no policy with IPsec action is needed; instead, routes are configured to direct traffic into the virtual interface. This is the opposite characteristic of using IP addresses and ports for traffic definition.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.