GRE tunnels can carry multicast traffic, and when combined with IPsec, the GRE packets are encrypted. This allows OSPF to form neighbor adjacencies over the tunnel because OSPF uses multicast (224.0.0.5/224.0.0.6). Native IPsec cannot carry multicast, so GRE over IPsec is the standard solution for dynamic routing protocols requiring multicast over a VPN.
Why this answer
IPsec security associations are inherently unicast and cannot carry multicast or broadcast traffic. To support OSPF, which relies on multicast hellos, the design must encapsulate multicast inside a GRE tunnel and then protect that GRE tunnel with IPsec. This is commonly called GRE over IPsec or IPsec profile applied to a GRE tunnel interface.
Exam trap
The trap here is believing that IPsec itself can carry multicast, when in fact IPsec SAs are point-to-point unicast and require GRE encapsulation for multicast support.