VPN
FCP-FGT-AD-7-6 · 23 questions
- A utility's NOC engineer is building a new site-to-site IPsec tunnel to a remote substation FortiGate. During IKE phase 1, the two devices must agree on how to protect the negotiation itself before any user traffic can be defined. Which set of parameters is negotiated in phase 1?
- During phase 2 of an IPsec negotiation between the utility's NOC FortiGate and a substation peer, the administrators must agree on which specific traffic will be encrypted and how the data-plane security association is protected. What does phase 2 primarily negotiate?
- A utility wants to add a new substation to its hub-and-spoke IPsec design and later run a dynamic routing protocol over the tunnel to automatically advertise reachable subnets. Which IPsec configuration approach best supports this goal?
- An OT maintenance vendor needs a permanent site-to-site IPsec tunnel into a utility's substation network so its engineers can remotely service protective relays. The vendor's edge device has a dynamic, unpredictable public IP address, while the utility's NOC FortiGate has a fixed IP. How should the NOC FortiGate be configured for phase 1?
- A utility is choosing how the NOC FortiGate will authenticate to a new substation FortiGate for a site-to-site IPsec tunnel. Compared with a pre-shared key, what is the main operational advantage of using certificate-based authentication for this pair of peers?
- A field-service technician connects to the utility's network from a truck using remote-access VPN to reach a work-order dispatch application, while all other internet traffic from the laptop should continue to go out the technician's own mobile hotspot instead of through the utility's network. Which VPN concept controls this behavior?
- A utility's NOC FortiGate has a route-based IPsec tunnel to a substation that is up and passing traffic. The security team notes that the tunnel interface alone does not restrict which hosts on the NOC side can reach which hosts on the substation side. What must still be configured for traffic to be properly controlled once it reaches the tunnel interface?
- A NOC engineer is troubleshooting a new site-to-site IPsec tunnel to a substation that never comes up at all. Checking the logs, phase 1 never completes and no security association is ever established. Which category of misconfiguration is the most likely cause?
- Phase 1 comes up cleanly between the NOC FortiGate and a substation peer, but phase 2 never establishes and no traffic passes across the tunnel. Which area should the engineer investigate first?
- A utility is designing IPsec connectivity from its NOC to twelve remote substations, and wants every substation to be able to reach every other substation directly for peer-to-peer protective relay coordination, without routing traffic through the NOC. Which IPsec VPN topology fits this requirement?
- A utility has forty substations but wants to limit the number of tunnels each substation FortiGate must maintain, while still giving the NOC central visibility and control over inter-substation traffic. Which topology trades off full mesh connectivity for that centralized control?
- The NOC's IPsec hub connects to twenty substations, and the utility wants three critical substations to keep talking to each other even if the NOC hub temporarily goes offline for maintenance, while the remaining seventeen substations can tolerate depending entirely on the hub. Which topology description matches this design?
- The utility wants an IPsec tunnel between the NOC and a substation to tear down automatically if the peer stops responding, rather than staying up as a stale, unusable security association that field technicians assume is still working. Which IPsec feature accomplishes this?
- Field technicians connecting to the utility's dispatch application over SSL VPN report that the tunnel mode client works fine, but their laptops sometimes need to reach dispatch through a plain web browser from a shared kiosk in a truck depot where no client software can be installed. Which SSL VPN access mode fits the kiosk scenario?
- A utility deploys remote-access VPN for field technicians using the FortiClient application, giving them a full virtual network adapter that lets applications behave as if the laptop is physically on the utility's internal network. Which SSL VPN access mode is being used?
- A utility security architect is reviewing remote-access VPN policy and wants field laptops to reach only the dispatch and billing subnets over the tunnel, sending all other traffic, including general internet browsing, out the laptop's own local connection. Which split tunneling configuration accomplishes this?
- A utility uses full-tunnel remote-access VPN so that all traffic from a technician's laptop, including general web browsing, is inspected by the NOC's FortiGate before reaching the internet. What operational cost does this design accept compared to split tunneling?
- A field technician's SSL VPN session repeatedly fails right after the technician enters valid credentials, while other technicians using the same portal connect successfully. The FortiGate's event log shows the authentication step succeeding, but the session tears down immediately afterward. Which layer of the problem should the engineer investigate next?
- A utility's NOC FortiGate has phase 1 configured with an 86400-second key lifetime for its tunnel to a substation, while the substation's older FortiGate still has phase 1 set to 28800 seconds. Both sides use matching encryption and authentication proposals. What is the most likely outcome?
- A substation FortiGate has two internet-facing WAN links for redundancy, and the utility wants the site-to-site IPsec tunnel to the NOC to automatically fail over to the backup WAN link if the primary link goes down, without an engineer having to reconfigure the tunnel by hand. Beyond the IPsec tunnel itself, what must also be addressed for this failover to actually work end to end?
- A NOC engineer sees an IPsec tunnel to a substation come up successfully (phase 1 and phase 2 both establish), but no traffic actually reaches hosts on the substation LAN even though the tunnel status shows as up. What is the most likely explanation to check first?
- An OT vendor's site-to-site IPsec tunnel to a substation was working for months, but after the vendor rotated their edge device's certificate, the tunnel stopped establishing phase 1 entirely. Which explanation best accounts for this specific failure pattern?
- A utility is standardizing its substation IPsec design and wants new engineers to understand why route-based tunnels are generally preferred over policy-based tunnels for sites likely to need dynamic routing, redundancy, or per-application firewall control later. What is the core structural difference that explains this preference?