NSE7 Advanced VPN and Zero Trust Practice Question
You run the following command on a FortiGate: 'diagnose vpn ike gateway list' and see that the DPD status for a VPN peer is 'dead'. What does this indicate?
⚠ Common exam trap
NSE7 often tests the meaning of DPD statuses, so candidates may confuse 'dead' with a still-up tunnel or an expired IPsec SA, but 'dead' specifically means the peer is unreachable and the tunnel is down.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VPN peer has been detected as unreachable and the tunnel is considered down
When 'diagnose vpn ike gateway list' shows DPD status as 'dead', it means the FortiGate has not received DPD (Dead Peer Detection) responses from the peer within the configured retry period, so it considers the peer unreachable and tears down the tunnel. The IKE SA and IPsec SAs are removed, and the tunnel is considered down. This is the correct interpretation of the 'dead' status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The remote peer has been manually disconnected from the network
Why it's wrong here
DPD dead reflects missed heartbeat probes, not an administrative disconnect; a manual teardown would remove the gateway entry or show it as down without DPD failure. It is tempting because an offline peer also stops responding, but DPD cannot distinguish that cause from any other silence.
- ✗
The VPN tunnel is still up but the peer is not responding to DPD messages
Why it's wrong here
A dead DPD status means the peer stopped answering DPD probes, so FortiGate tears down or marks the tunnel down rather than keeping it up. It is tempting because DPD does detect unresponsive peers, but the status itself signals failure, not a still-functioning tunnel.
- ✗
The IKE SA is still active but the IPsec SA has expired
Why it's wrong here
DPD status reflects peer reachability via dead peer detection, not IPsec SA lifetime; an expired IPsec SA would show as a separate rekey or SA state, while the IKE SA can remain. It is tempting because SA expiry does disrupt traffic, but that is a distinct condition from a dead peer.
- ✓
The VPN peer has been detected as unreachable and the tunnel is considered down
Why this is correct
DPD 'dead' means the FortiGate sent dead peer detection probes and received no response within the configured retry interval, so the peer is treated as unreachable and the tunnel torn down. This differs from an idle but responsive peer, which reports 'alive'.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the primary purpose of Dead Peer Detection (DPD) in an IPsec VPN configuration?
easy- A.To establish a backup tunnel in case the primary tunnel fails.
- ✓ B.To detect if a VPN peer is alive by sending periodic probes and bringing down the tunnel if no response is received.
- C.To automatically renegotiate IKE phase1 keys before they expire.
- D.To verify the integrity of encrypted packets using HMAC authentication.
Why B: Dead Peer Detection (DPD) sends periodic R-U-THERE probes (RFC 3706) to a VPN peer and expects an R-U-THERE-ACK response. If no response arrives within a configured threshold, DPD declares the peer dead and tears down the tunnel, allowing failover or renegotiation. This prevents traffic from being black-holed into a dead tunnel.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.