NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?
⚠ Common exam trap
NSE7 often tests the confusion between authentication method and other phase1 parameters like DH groups or peer ID options, causing candidates to overlook that 'authentication-method' must be explicitly set to 'signature' to enable certificate-based authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the authentication method to 'signature'.
In FortiOS IPsec phase1 configuration, the 'authentication-method' parameter controls how the peers authenticate during IKEv2. Setting it to 'signature' instructs the FortiGate to use digital signatures (RSA or ECDSA) with X.509 certificates instead of pre-shared keys. This is the mandatory change to enable certificate-based authentication; other parameters like 'certificate' and 'remote-certificate' are then used to specify the actual certificates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the authentication method to 'signature'.
Why this is correct
Setting the phase1 authentication method to 'signature' replaces pre-shared key authentication with digital certificate exchange, satisfying the requirement for PKI-based IKEv2 authentication. FortiGate then validates peer certificates against the configured CA, using RSA or ECDSA signatures during the IKEv2 exchange rather than a shared secret.
- ✗
Set the proposal to include DH groups 14 or higher.
Why it's wrong here
DH groups control key exchange strength during IKE negotiation, not the authentication method; certificates still require the authentication parameter to change. It is tempting because stronger DH groups accompany hardened VPN setups, but they do not switch phase1 from pre-shared keys to certificate-based authentication.
- ✗
Configure 'local-gw' with the certificate's CN.
Why it's wrong here
Setting local-gw to the certificate CN misuses a field that specifies the local gateway IP or FQDN for the IKE endpoint; certificate identity is carried in the certificate itself, not this parameter. It is tempting because CN values do appear in peer identification, but local-gw never selects certificate authentication.
- ✗
Enable 'peer-id-option' and set it to 'any'.
Why it's wrong here
peer-id-option governs how the remote peer's identity is validated against its certificate, not whether certificates replace pre-shared keys. It is tempting because peer ID handling matters in certificate IKE, but enabling it does not change the authentication method from PSK to certificates.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?
easy- ✓ A.set authmethod signature
- B.set cert-validation enable
- C.set ike-version 2
- D.set peer-id certificate
Why A: In FortiGate IPsec phase1 configuration, certificate-based authentication is enabled by setting authmethod to signature, which tells the FortiGate to use digital signatures (certificates) instead of pre-shared keys. This is the specific phase1 parameter that switches authentication from PSK to certificate-based.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.