Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?

⚠ Common exam trap

NSE7 often tests the meaning of DPD statuses, so candidates may confuse 'dead' with a still-up tunnel or an expired IPsec SA, but 'dead' specifically means the peer is unreachable and the tunnel is down.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VPN peer has been detected as unreachable and the tunnel is considered down

When 'diagnose vpn ike gateway list' shows DPD status as 'dead', it means the FortiGate has not received DPD (Dead Peer Detection) responses from the peer within the configured retry period, so it considers the peer unreachable and tears down the tunnel. The IKE SA and IPsec SAs are removed, and the tunnel is considered down. This is the correct interpretation of the 'dead' status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The remote peer has been manually disconnected from the network

    Why it's wrong here

    DPD dead reflects missed heartbeat probes, not an administrative disconnect; a manual teardown would remove the gateway entry or show it as down without DPD failure. It is tempting because an offline peer also stops responding, but DPD cannot distinguish that cause from any other silence.

  • ✗

    The VPN tunnel is still up but the peer is not responding to DPD messages

    Why it's wrong here

    A dead DPD status means the peer stopped answering DPD probes, so FortiGate tears down or marks the tunnel down rather than keeping it up. It is tempting because DPD does detect unresponsive peers, but the status itself signals failure, not a still-functioning tunnel.

  • ✗

    The IKE SA is still active but the IPsec SA has expired

    Why it's wrong here

    DPD status reflects peer reachability via dead peer detection, not IPsec SA lifetime; an expired IPsec SA would show as a separate rekey or SA state, while the IKE SA can remain. It is tempting because SA expiry does disrupt traffic, but that is a distinct condition from a dead peer.

  • ✓

    The VPN peer has been detected as unreachable and the tunnel is considered down

    Why this is correct

    DPD 'dead' means the FortiGate sent dead peer detection probes and received no response within the configured retry interval, so the peer is treated as unreachable and the tunnel torn down. This differs from an idle but responsive peer, which reports 'alive'.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?

easy
  • A.To establish a backup tunnel in case the primary tunnel fails.
  • ✓ B.To detect if a VPN peer is alive by sending periodic probes and bringing down the tunnel if no response is received.
  • C.To automatically renegotiate IKE phase1 keys before they expire.
  • D.To verify the integrity of encrypted packets using HMAC authentication.

Why B: Dead Peer Detection (DPD) sends periodic R-U-THERE probes (RFC 3706) to a VPN peer and expects an R-U-THERE-ACK response. If no response arrives within a configured threshold, DPD declares the peer dead and tears down the tunnel, allowing failover or renegotiation. This prevents traffic from being black-holed into a dead tunnel.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.