Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is troubleshooting an IPsec VPN where Phase 1 completes but Phase 2 fails to establish. The administrator reviews the Phase 2 configuration and notices that the local and remote subnets do not match between the two peers. Which action should the administrator take to resolve the Phase 2 failure?

⚠ Common exam trap

The trap here is assuming Phase 2 failures are caused by Phase 1 settings, when a selector mismatch is the actual cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adjust the Phase 2 selectors on both peers so the local and remote subnet definitions mirror each other.

Phase 2 selectors must mirror each other: one peer's local subnet must equal the other peer's remote subnet. When they do not match, the child SA negotiation fails even though Phase 1 succeeds. Aligning the selectors on both peers restores the correct traffic selectors and allows Phase 2 to complete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the Phase 1 lifetime so the tunnel stays up longer during renegotiation.

    Why it's wrong here

    Phase 1 lifetime controls how often the IKE SA is rekeyed; it does not influence whether Phase 2 selectors match. Extending the lifetime would not fix a selector mismatch and could delay detection of other issues. The problem is in the Phase 2 proposal, not in Phase 1 timing.

  • ✓

    Adjust the Phase 2 selectors on both peers so the local and remote subnet definitions mirror each other.

    Why this is correct

    Phase 2 selectors define which traffic is encrypted. If the local subnet on one peer does not correspond to the remote subnet on the other, the proposal does not match and Phase 2 fails. Aligning the selectors so each peer's local subnet equals the other's remote subnet resolves the mismatch and allows the child SA to establish.

  • ✗

    Enable PFS on both peers and set the same Diffie-Hellman group.

    Why it's wrong here

    PFS affects key material generation for Phase 2 but does not correct a subnet mismatch. Enabling PFS without fixing the selectors would still result in a Phase 2 failure, because the traffic selectors would not match. PFS is a security enhancement, not a remedy for selector misalignment.

  • ✗

    Change the Phase 1 authentication method from pre-shared key to certificates on both peers.

    Why it's wrong here

    Phase 1 authentication governs peer identity and has already succeeded, since Phase 1 completes. Changing it to certificates would not address a Phase 2 selector mismatch and could introduce new trust issues. The failure is in the child SA negotiation, not in peer authentication.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.