GSEC Cryptography Practice Question
A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?
⚠ Common exam trap
The trap here is thinking that PSK is sent in plaintext or that it prevents PFS, when the real risk is offline dictionary attacks against a shared secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PSK authentication is vulnerable to offline dictionary attacks if an attacker captures the handshake.
Pre-shared key authentication in IKEv2 relies on a secret that is shared among peers. If an attacker captures the authentication exchange, they can attempt to guess the PSK offline, especially if it is weak. This makes PSK authentication vulnerable to dictionary attacks, which is a primary security concern compared to certificate-based authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PSK authentication cannot be used with IKEv2; it requires IKEv1.
Why it's wrong here
IKEv2 fully supports pre-shared key authentication. This option is factually incorrect; both IKEv1 and IKEv2 can use PSKs. The concern is not protocol support but the security weaknesses of PSKs. Therefore, this option is not a valid primary security concern.
- ✗
PSK authentication does not encrypt the IKEv2 handshake, exposing the PSK in plaintext.
Why it's wrong here
The IKEv2 handshake is encrypted after the initial exchange, and the PSK itself is never sent in plaintext. Instead, it is used to generate authentication payloads. So the PSK is not exposed directly. The actual risk is offline dictionary attacks, not plaintext exposure. This option misrepresents how PSK authentication works.
- ✓
PSK authentication is vulnerable to offline dictionary attacks if an attacker captures the handshake.
Why this is correct
In IKEv2 with PSK, the authentication exchange involves a hash of the PSK and other values. An attacker who captures the handshake can perform an offline dictionary attack to recover the PSK if it is weak. This is a serious concern because PSKs are often human-chosen and may be susceptible to guessing. Unlike certificate-based authentication, there is no public key infrastructure to provide strong authentication.
- ✗
PSK authentication does not provide perfect forward secrecy (PFS).
Why it's wrong here
Perfect forward secrecy is a property of key exchange, not authentication. IKEv2 with PSK can still use Diffie-Hellman for key exchange to achieve PFS. The primary concern with PSK is not the lack of PFS but the fact that the same secret is shared among multiple parties, increasing the risk of compromise. So this option misidentifies the main issue.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.