exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 505 discussion

Actual exam question from CompTIA's CAS-004
Question #: 505
Topic #: 1
[All CAS-004 Questions]

A security technician is trying to connect a remote site to the central office over a site-to-site VPN. The technician has verified the source and destination IP addresses are correct, but the technician is unable to get the remote site to connect. The following error message keeps repeating:

An error has occurred during Phase 1 handshake. Deleting keys and retrying...

Which of the following is most likely the reason the connection is failing?

  • A. The IKE hashing algorithm uses different key lengths on each VPN device.
  • B. The IPSec settings allow more than one cipher suite on both devices.
  • C. The Diffie-Hellman group on both sides matches but is a legacy group.
  • D. The remote VPN is attempting to connect with a protocol other than SSL/TLS.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
0e4eff2
4 days, 3 hours ago
Selected Answer: C
The error indicates an issue during Phase 1 of the IKE handshake, which is used for establishing secure key exchange in IPSec VPNs. If the Diffie-Hellman group is legacy (e.g., Group 1 or 2), it might no longer be supported by modern systems, causing the connection to fail. Updating to a stronger Diffie-Hellman group (e.g., Group 14 or 19) resolves this issue.
upvoted 1 times
...
gbemimatti
4 months, 3 weeks ago
Selected Answer: A
The error message indicates a failure during Phase 1 handshake, which is part of the IKE (Internet Key Exchange) process. IKE Phase 1 establishes a secure and authenticated channel for negotiating IPSec parameters. A mismatch in cryptographic settings, such as the hashing algorithm or key lengths, is a common cause of this type of failure.
upvoted 3 times
...
a18733c
5 months ago
Selected Answer: A
The error message indicates a failure during the Phase 1 handshake of the VPN connection. Phase 1 establishes a secure channel for negotiating and authenticating the VPN connection. A mismatch in cryptographic parameters, such as the IKE (Internet Key Exchange) hashing algorithm or key lengths, is a common cause of such errors.
upvoted 3 times
...
Bright07
6 months, 3 weeks ago
Ans. A. The error message "An error has occurred during Phase 1 handshake" suggests a problem during the initial negotiation of the VPN tunnel, often related to mismatches in configuration settings. The most likely reason for the connection failure is: A. The IKE hashing algorithm uses different key lengths on each VPN device. Inconsistent configurations between the two devices regarding the IKE settings, such as key lengths or hashing algorithms, can lead to failure in the Phase 1 handshake.
upvoted 3 times
...
CiscoExam94
7 months, 3 weeks ago
Selected Answer: C
The Diffie-Hellman group on both sides matches but is a legacy group. Legacy DH groups (such as Group 1 or Group 2) are considered weak and may not be supported by modern security policies or configurations. If the DH group is outdated, it could cause the IKE Phase 1 handshake to fail, prompting errors related to key exchange issues.
upvoted 3 times
...
PluDou_111
8 months, 3 weeks ago
Selected Answer: A
A. The IKE hashing algorithm uses different key lengths on each VPN device. In a site-to-site VPN setup, both ends must use compatible settings for the VPN to establish successfully. This includes parameters like the IKE hashing algorithm, encryption algorithm, and Diffie-Hellman group. If the hashing algorithms (or their key lengths) do not match on both sides, the IKE Phase 1 negotiation will fail, causing the error message described.
upvoted 4 times
...
23169fd
9 months ago
Selected Answer: C
The error message “An error has occurred during Phase 1 handshake. Deleting keys and retrying…” suggests that there is an issue with the initial negotiation or key exchange process. Legacy Diffie-Hellman groups are a common cause of such issues because modern VPN devices might reject or fail to negotiate with older, less secure groups.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago