Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)

⚠ Common exam trap

The trap here is assuming that selecting a certificate in phase 1 is sufficient, when the FortiGate also needs the matching private key and a trusted CA for the peer certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that the peer certificate is signed by a CA that is imported into the FortiGate and that the CA is used for peer authentication.

Certificate-based IKEv2 requires both sides to present a local certificate with a usable private key and to validate the peer certificate against a trusted CA. The negotiation failure after certificate exchange points to a problem with the local certificate and key or with the CA used to validate the peer. Importing the correct CA and confirming the local certificate selection are the two actions that directly address these requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure that the peer certificate is signed by a CA that is imported into the FortiGate and that the CA is used for peer authentication.

    Why this is correct

    The FortiGate validates the peer certificate against a trusted CA. If the issuing CA is not imported or not referenced in the phase 1 peer authentication settings, the certificate exchange completes but validation fails. Importing the correct CA and selecting it for peer authentication is necessary for the tunnel to proceed past certificate validation.

  • ✗

    Configure the phase 1 proposal to use pre-shared key authentication instead of certificate authentication to bypass certificate validation.

    Why it's wrong here

    Switching to pre-shared key authentication changes the authentication method and does not resolve a certificate configuration problem. It would also require reconfiguring the remote peer and may not meet the security requirements that prompted certificate use. The goal is to fix the certificate setup, not to replace the authentication method.

  • ✗

    Disable Dead Peer Detection on the phase 1 configuration so that the certificate exchange is not interrupted.

    Why it's wrong here

    DPD is used to detect dead peers and does not interfere with certificate exchange during IKE negotiation. Disabling it would remove a useful failure-detection mechanism without addressing the certificate validation failure. The tunnel is failing before it is established, so DPD is not the cause.

  • ✗

    Set the phase 1 mode to aggressive instead of main mode to speed up certificate negotiation.

    Why it's wrong here

    IKEv2 does not use main or aggressive mode; those are IKEv1 concepts. Even in IKEv1, changing the mode does not fix a missing private key or an untrusted CA. This option introduces an incorrect protocol behavior and would not resolve the certificate-related failure described.

  • ✓

    Verify that the local certificate used for IPsec is selected in the phase 1 configuration and that its private key is present on the FortiGate.

    Why this is correct

    For certificate-based IKEv2, the FortiGate must use a local certificate whose private key is available to sign the IKE authentication payload. If the certificate is selected but the private key is missing or mismatched, the negotiation fails after the certificate exchange. Confirming the local certificate selection and key presence directly addresses the failure point.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.