Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?

⚠ Common exam trap

Watch out — candidates often confuse security features like PFS or fragmentation with the liveness detection provided by DPD.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dead Peer Detection (DPD) with the mode set to on-idle or always.

Dead Peer Detection is the IPsec mechanism that monitors peer liveness by sending probes or waiting for idle periods. When the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures continuous monitoring, enabling automatic tunnel recovery without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Dead Peer Detection (DPD) with the mode set to on-idle or always.

    Why this is correct

    DPD is the IPsec feature that detects when a peer becomes unreachable. When enabled, the FortiGate sends periodic probes or waits for idle traffic before probing. If the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures detection occurs and the tunnel can be automatically re-established without manual intervention.

  • ✗

    Automatic Key Negotiation (AutoIKE) to dynamically negotiate new SAs.

    Why it's wrong here

    There is no FortiGate feature called Automatic Key Negotiation or AutoIKE for this purpose. IKE itself negotiates SAs, but it does not independently detect peer failures. DPD is the mechanism that monitors peer liveness and triggers renegotiation. AutoIKE is not a valid FortiGate configuration option, so it cannot be used to detect peer failures and automatically re-establish the tunnel.

  • ✗

    Perfect Forward Secrecy (PFS) to generate new keys for each phase 2 negotiation.

    Why it's wrong here

    PFS ensures that compromise of one key does not compromise previous or future keys by generating new keys during phase 2. It enhances security but does not detect peer failures or trigger renegotiation. The tunnel could remain down if the peer is unreachable, regardless of PFS. Therefore, PFS does not satisfy the requirement for automatic failure detection and re-establishment.

  • ✗

    IKEv2 fragmentation to allow large packets to traverse the tunnel.

    Why it's wrong here

    IKEv2 fragmentation addresses issues with large IKE packets being dropped by intermediate devices. It does not detect peer failures or trigger tunnel renegotiation. While useful for interoperability, it is not the feature that monitors peer availability. DPD is specifically designed for failure detection, so IKEv2 fragmentation does not meet the requirement of automatic tunnel re-establishment after a peer failure.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.