Courseiva
Cryptography →mediumMultiple Choice

GSEC Cryptography Practice Question

A security analyst is reviewing the configuration of a VPN gateway that uses IPsec in tunnel mode. The analyst notices that the gateway is configured to use IKEv2 with a pre-shared key (PSK) for authentication. Which of the following is the PRIMARY security concern with this configuration?

⚠ Common exam trap

The trap here is thinking that PSK is sent in plaintext or that it prevents PFS, when the real risk is offline dictionary attacks against a shared secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PSK authentication is vulnerable to offline dictionary attacks if an attacker captures the handshake.

Pre-shared key authentication in IKEv2 relies on a secret that is shared among peers. If an attacker captures the authentication exchange, they can attempt to guess the PSK offline, especially if it is weak. This makes PSK authentication vulnerable to dictionary attacks, which is a primary security concern compared to certificate-based authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PSK authentication cannot be used with IKEv2; it requires IKEv1.

    Why it's wrong here

    IKEv2 fully supports pre-shared key authentication. This option is factually incorrect; both IKEv1 and IKEv2 can use PSKs. The concern is not protocol support but the security weaknesses of PSKs. Therefore, this option is not a valid primary security concern.

  • ✗

    PSK authentication does not encrypt the IKEv2 handshake, exposing the PSK in plaintext.

    Why it's wrong here

    The IKEv2 handshake is encrypted after the initial exchange, and the PSK itself is never sent in plaintext. Instead, it is used to generate authentication payloads. So the PSK is not exposed directly. The actual risk is offline dictionary attacks, not plaintext exposure. This option misrepresents how PSK authentication works.

  • ✓

    PSK authentication is vulnerable to offline dictionary attacks if an attacker captures the handshake.

    Why this is correct

    In IKEv2 with PSK, the authentication exchange involves a hash of the PSK and other values. An attacker who captures the handshake can perform an offline dictionary attack to recover the PSK if it is weak. This is a serious concern because PSKs are often human-chosen and may be susceptible to guessing. Unlike certificate-based authentication, there is no public key infrastructure to provide strong authentication.

  • ✗

    PSK authentication does not provide perfect forward secrecy (PFS).

    Why it's wrong here

    Perfect forward secrecy is a property of key exchange, not authentication. IKEv2 with PSK can still use Diffie-Hellman for key exchange to achieve PFS. The primary concern with PSK is not the lack of PFS but the fact that the same secret is shared among multiple parties, increasing the risk of compromise. So this option misidentifies the main issue.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.