exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 429 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 429
Topic #: 1
[All PCNSE Questions]

A network administrator is troubleshooting an issue with Phase 2 of an IPSec VPN tunnel. The administrator determines that the lifetime needs to be changed to match the peer.

Where should this change be made?

  • A. IKE Gateway profile
  • B. IPSec Crypto profile
  • C. IKE Crypto profile
  • D. IPSec Tunnel settings
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Marshpillowz
11 months, 2 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
Sammy3637
1 year, 1 month ago
Selected Answer: B
contains - ESP/AH , Encryption , Authentication , DH Group ,Lifetime and Lifesize
upvoted 2 times
...
tolis2007
1 year, 10 months ago
It's obviously B. I really don't understand how the creators are doing so many mistakes on the questions... even in simple ones
upvoted 2 times
62c930f
1 month, 3 weeks ago
the mistakes are made intentionally to prevent the website from being shut down. They rely on the users to discuss and provide the actual correct answers :)
upvoted 1 times
...
...
mohr22
1 year, 11 months ago
B for phase 2 ....... - For securing communication across the VPN tunnel, the firewall requires IKE and IPSec cryptographic profiles for completing IKE phase 1 and phase 2 negotiations, respectively.
upvoted 1 times
...
djedeen
1 year, 12 months ago
Selected Answer: B
B: Details for both phases of IKE: The **IKE crypto profile** is used to set up the encryption and authentication algorithms used for the key exchange process in IKE Phase 1, and lifetime of the keys, which specifies how long the keys are valid. To invoke the profile, you must attach it to the IKE Gateway configuration. The **IPSec crypto profile** is invoked in IKE Phase 2. It specifies how the data is secured within the tunnel when Auto Key IKE is used to automatically generate keys for the IKE SAs.
upvoted 3 times
...
19216855
2 years ago
Selected Answer: B
B chrisy042's link
upvoted 2 times
...
confusion
2 years, 1 month ago
Selected Answer: B
B chrisy042's link explains
upvoted 2 times
...
mz101
2 years, 1 month ago
Yes, should be B
upvoted 3 times
...
chrisy042
2 years, 1 month ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/vpns/set-up-site-to-site-vpn/define-cryptographic-profiles/define-ipsec-crypto-profiles
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago