A server is configured to encrypt all incoming traffic using a connection security rule. You need to allow that server (Server1) to reply to unencrypted tracert commands from hosts on the same network. What should you configure in Windows Defender Firewall with Advanced Security?
Choose an answer
Tap an option to check your answer.
Correct answer: From the IPsec Settings, configure IPsec exemptions..
Why this is the answer
The correct answer is to configure IPsec exemptions. This allows specific traffic, like the unencrypted tracert (ICMPv4) commands, to bypass the IPsec connection security rules that enforce encryption. By adding an exemption for ICMPv4, Server1 can respond to these commands without violating its encryption policy for other traffic. Configuring IPsec defaults would apply general settings but not specifically exempt unencrypted traffic. Creating a new custom outbound rule might allow ICMPv4, but it wouldn't override the existing connection security rule requiring encryption for all traffic. Changing the Firewall state to Off for the Private profile would disable the firewall entirely, which is a security risk and not a targeted solution.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed