A regulated customer must implement an IKEv2 custom policy on their Azure VPN gateway requiring strong encryption and Perfect Forward Secrecy (PFS). Which statements are true for successfully configuring an IKEv2 custom policy so the tunnel comes up with PFS enforced?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure matching IKE phase 1 and phase 2 proposals on both peers; include an IKEv2 proposal with the required DH group for IKE and a separate PFS group for IPSec (phase 2). Both peers must have identical policy order and parameter match (encryption, integrity, DH/PFS)..
Why this is the answer
The correct answer emphasizes that for IKEv2 custom policies with PFS, both VPN peers must have matching IKE phase 1 (main mode) and phase 2 (quick mode) proposals. This includes identical encryption, integrity, Diffie-Hellman (DH) group for IKE phase 1, and Perfect Forward Secrecy (PFS) group for IPSec phase 2. The policy order and all parameters must align for the tunnel to establish correctly with PFS enforced. Incorrect options are wrong because: "Only the IKE phase 1 DH group matters..." is false; PFS explicitly requires a separate DH group for IPSec phase 2. "Set the encryption algorithm on the gateway to AES-128 and rely on Azure to negotiate a stronger cipher..." is incorrect; custom policies require explicit matching, and Azure does not automatically negotiate stronger ciphers or handle PFS optionally in this context. "Enable PFS on the Azure VPN gateway GUI slider; Azure will then accept any mismatched DH/PFS groups..." is incorrect; custom policies require strict matching, and Azure does not perform group translation for mismatched PFS groups.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed