Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator wants to use PKI certificates for IKEv2 authentication instead of pre-shared keys. Which phase1 configuration parameter must be changed to support certificate-based authentication?

⚠ Common exam trap

NSE7 often tests the confusion between authentication method and other phase1 parameters like DH groups or peer ID options, causing candidates to overlook that 'authentication-method' must be explicitly set to 'signature' to enable certificate-based authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the authentication method to 'signature'.

In FortiOS IPsec phase1 configuration, the 'authentication-method' parameter controls how the peers authenticate during IKEv2. Setting it to 'signature' instructs the FortiGate to use digital signatures (RSA or ECDSA) with X.509 certificates instead of pre-shared keys. This is the mandatory change to enable certificate-based authentication; other parameters like 'certificate' and 'remote-certificate' are then used to specify the actual certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the authentication method to 'signature'.

    Why this is correct

    Setting the phase1 authentication method to 'signature' replaces pre-shared key authentication with digital certificate exchange, satisfying the requirement for PKI-based IKEv2 authentication. FortiGate then validates peer certificates against the configured CA, using RSA or ECDSA signatures during the IKEv2 exchange rather than a shared secret.

  • ✗

    Set the proposal to include DH groups 14 or higher.

    Why it's wrong here

    DH groups control key exchange strength during IKE negotiation, not the authentication method; certificates still require the authentication parameter to change. It is tempting because stronger DH groups accompany hardened VPN setups, but they do not switch phase1 from pre-shared keys to certificate-based authentication.

  • ✗

    Configure 'local-gw' with the certificate's CN.

    Why it's wrong here

    Setting local-gw to the certificate CN misuses a field that specifies the local gateway IP or FQDN for the IKE endpoint; certificate identity is carried in the certificate itself, not this parameter. It is tempting because CN values do appear in peer identification, but local-gw never selects certificate authentication.

  • ✗

    Enable 'peer-id-option' and set it to 'any'.

    Why it's wrong here

    peer-id-option governs how the remote peer's identity is validated against its certificate, not whether certificates replace pre-shared keys. It is tempting because peer ID handling matters in certificate IKE, but enabling it does not change the authentication method from PSK to certificates.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator wants to use PKI certificates for IPsec VPN authentication instead of pre-shared keys. Which phase1 parameter must be set to 'signature' to enable certificate-based authentication?

easy
  • ✓ A.set authmethod signature
  • B.set cert-validation enable
  • C.set ike-version 2
  • D.set peer-id certificate

Why A: In FortiGate IPsec phase1 configuration, certificate-based authentication is enabled by setting authmethod to signature, which tells the FortiGate to use digital signatures (certificates) instead of pre-shared keys. This is the specific phase1 parameter that switches authentication from PSK to certificate-based.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.