NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is troubleshooting an IPsec VPN that uses IKEv2 and certificate authentication. The tunnel fails to establish, and the administrator sees that the phase 1 negotiation reaches the point of exchanging certificates but then fails. The administrator wants to verify the certificate-related configuration. Which two actions should the administrator take to resolve the issue? (Choose two.)
⚠ Common exam trap
The trap here is assuming that selecting a certificate in phase 1 is sufficient, when the FortiGate also needs the matching private key and a trusted CA for the peer certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that the peer certificate is signed by a CA that is imported into the FortiGate and that the CA is used for peer authentication.
Certificate-based IKEv2 requires both sides to present a local certificate with a usable private key and to validate the peer certificate against a trusted CA. The negotiation failure after certificate exchange points to a problem with the local certificate and key or with the CA used to validate the peer. Importing the correct CA and confirming the local certificate selection are the two actions that directly address these requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure that the peer certificate is signed by a CA that is imported into the FortiGate and that the CA is used for peer authentication.
Why this is correct
The FortiGate validates the peer certificate against a trusted CA. If the issuing CA is not imported or not referenced in the phase 1 peer authentication settings, the certificate exchange completes but validation fails. Importing the correct CA and selecting it for peer authentication is necessary for the tunnel to proceed past certificate validation.
- ✗
Configure the phase 1 proposal to use pre-shared key authentication instead of certificate authentication to bypass certificate validation.
Why it's wrong here
Switching to pre-shared key authentication changes the authentication method and does not resolve a certificate configuration problem. It would also require reconfiguring the remote peer and may not meet the security requirements that prompted certificate use. The goal is to fix the certificate setup, not to replace the authentication method.
- ✗
Disable Dead Peer Detection on the phase 1 configuration so that the certificate exchange is not interrupted.
Why it's wrong here
DPD is used to detect dead peers and does not interfere with certificate exchange during IKE negotiation. Disabling it would remove a useful failure-detection mechanism without addressing the certificate validation failure. The tunnel is failing before it is established, so DPD is not the cause.
- ✗
Set the phase 1 mode to aggressive instead of main mode to speed up certificate negotiation.
Why it's wrong here
IKEv2 does not use main or aggressive mode; those are IKEv1 concepts. Even in IKEv1, changing the mode does not fix a missing private key or an untrusted CA. This option introduces an incorrect protocol behavior and would not resolve the certificate-related failure described.
- ✓
Verify that the local certificate used for IPsec is selected in the phase 1 configuration and that its private key is present on the FortiGate.
Why this is correct
For certificate-based IKEv2, the FortiGate must use a local certificate whose private key is available to sign the IKE authentication payload. If the certificate is selected but the private key is missing or mismatched, the negotiation fails after the certificate exchange. Confirming the local certificate selection and key presence directly addresses the failure point.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.