exam questions

Exam JN0-1330 All Questions

View all questions & answers for the JN0-1330 exam

Exam JN0-1330 topic 1 question 59 discussion

Actual exam question from Juniper's JN0-1330
Question #: 59
Topic #: 1
[All JN0-1330 Questions]

An auditor reviewed your companys firewall configurations and is requiring that IPsec VPN connections must not expose IKE identities during IKE negotiations.
Which two methods satisfy this requirement? (Choose two.)

  • A. Use main mode for the IKE policy.
  • B. Use aggressive mode for the IKE policy.
  • C. Use IKEv2 instead of IKEv1.
  • D. Configure GRE over IPsec.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Main Mode and Aggressive Mode -
IKE phase 1 negotiations are used to establish IKE SAs. These SAs protect the IKE phase 2 negotiations. IKE uses one of two modes for phase 1 negotiations: main mode or aggressive mode. The choice of main or aggressive mode is a matter of tradeoffs. Some of the characteristics of the two modes are:
✑ Main mode
- Protects the identities of the peers during negotiations and is therefore more secure.
- Enables greater proposal flexibility than aggressive mode.
- Is more time consuming than aggressive mode because more messages are exchanged between peers. (Six messages are exchanged in main mode.)
✑ Aggressive mode
- Exposes identities of the peers to eavesdropping, making it less secure than main mode.
- Is faster than main mode because fewer messages are exchanged between peers. (Three messages are exchanged in aggressive mode.)
- Enables support for fully qualified domain names (FQDNs) when the router uses preshared keys.
Reference: https://www.juniper.net/techpubs/en_US/junose10.3/information-products/topic-collections/swconfig-ip-services/id-79352.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kumaravinash92
4 years, 4 months ago
AC is right
upvoted 1 times
...
Babai
4 years, 6 months ago
Correct answers A & C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago