Be able to read IKE and IPsec CLI output, run the right debug to isolate a failed tunnel, and configure GlobalProtect gateway selection and packet capture correctly. The single most important thing: match phase 2 proxy-IDs and proposals exactly on both peers.
Start practicing
Secure Access and VPN — choose a session length
Free · No account required
Domain overview
Secure Access and VPN covers IPsec site-to-site tunnels, GlobalProtect gateway and portal configuration, and SSL/IPsec remote access on PAN-OS. Questions are scenario-based: you diagnose IKE or IPsec failures from CLI output, choose the right debug or packet capture, and reason about gateway selection, routing, and proxy IDs.
Exam objectives
IKE phase 1 and phase 2 negotiation, proposal mismatch, and proxy-ID troubleshooting
Debug and verification commands such as test vpn ike-sa and show vpn ipsec-sa
GlobalProtect portal, gateway, agent configuration, and gateway selection logic
Packet capture feature: filters, stages, and export on the firewall
Assuming phase 2 'no proposal chosen' is a PSK or peer problem when it is usually a mismatched proxy-ID, encryption, or hash setting.
Forgetting that GlobalProtect gateway selection depends on source region, priority, and agent config, not just geographic proximity.
Running packet capture without setting the correct stage or filter, so the captured traffic never shows the failing IKE or ESP packets.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?
2Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?
3Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.
4A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?
5An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?
6When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?
7Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?
8Which THREE of the following are capabilities of GlobalProtect Host Information Profile (HIP)?
9An organization has two sites connected via IPSec VPN. The tunnel is up, but ICMP traffic between sites fails. No other traffic works. The firewall policy allows any-any. What is the most likely issue?
10Refer to the exhibit. A network engineer sees multiple IKE SAs for the same peer. What does this indicate?
11Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?
12A company is deploying GlobalProtect for remote users and wants to enforce that only users with valid certificates are allowed to connect. Which configuration is required on the GlobalProtect gateway?
13A network administrator is troubleshooting an IPsec site-to-site VPN that fails to establish. IKE phase 1 completes successfully, but phase 2 fails with a 'no proposal chosen' message. Both sides have identical IKE and IPsec crypto profiles, and the pre-shared key is correct. What is the most likely cause of the failure?
14Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)
15A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?
16A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?
17A network security engineer is configuring a route-based IPsec VPN between two Palo Alto Networks firewalls. The engineer needs to ensure that the tunnel interface is used for dynamic routing updates and that the VPN can fail over to a backup path if the primary path goes down. Which configuration is required to achieve this?
18A network engineer is configuring a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party VPN peer. The engineer wants to ensure that the firewall can establish the tunnel even if the peer initiates the connection. Which configuration is required on the Palo Alto Networks firewall?
19An administrator is configuring GlobalProtect with certificate authentication. The portal is configured to use a certificate profile that validates client certificates against a trusted CA. Users report that authentication fails with the error 'Certificate validation failed'. The administrator has verified that the client certificates are issued by the correct CA and are not expired. What is the most likely cause of the failure?
20A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?
21A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to read IKE and IPsec CLI output, run the right debug to isolate a failed tunnel, and configure GlobalProtect gateway selection and packet capture correctly. The single most important thing: match phase 2 proxy-IDs and proposals exactly on both peers.
The Courseiva PCNSE question bank contains 21 questions in the Secure Access and VPN domain, covering the 10% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Secure Access and VPN domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included