Courseiva
Secure Access and VPN →mediumMultiple Choice

PCNSE Secure Access and VPN Practice Question

A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?

⚠ Common exam trap

Candidates often confuse the IKE Crypto profile with the IPsec Crypto profile, or thinking that PFS is configured at the gateway or tunnel level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the IPsec Crypto profile, set the DH Group to group14.

Perfect Forward Secrecy for IKE phase 2 is configured in the IPsec Crypto profile. The DH Group field in this profile specifies the Diffie-Hellman group used for PFS during phase 2. Setting it to group14 ensures that the IPsec SA uses PFS with group14. The IKE Crypto profile controls phase 1, while the IPsec Crypto profile controls phase 2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In the IKE Gateway configuration, enable 'Perfect Forward Secrecy' and select group14.

    Why it's wrong here

    There is no such setting in the IKE Gateway configuration. PFS is not configured at the gateway level; it is part of the crypto profiles. The IKE Gateway defines the peer address, authentication, and advanced options like NAT traversal, but not PFS.

  • ✗

    In the IKE Crypto profile, set the DH Group to group14.

    Why it's wrong here

    The IKE Crypto profile is used for IKE phase 1, not phase 2. Setting the DH group in the IKE Crypto profile affects the initial key exchange for IKE SA, but does not control PFS for the IPsec SA. PFS for phase 2 is configured in the IPsec Crypto profile.

  • ✓

    In the IPsec Crypto profile, set the DH Group to group14.

    Why this is correct

    The IPsec Crypto profile is used for IKE phase 2 and includes the DH Group setting for PFS. By setting the DH Group to group14 in the IPsec Crypto profile, the firewall will propose PFS with group14 during phase 2, ensuring that the IPsec SA uses PFS with the specified group.

  • ✗

    In the IPsec Tunnel configuration, enable 'Perfect Forward Secrecy' and select group14.

    Why it's wrong here

    The IPsec Tunnel configuration is where you bind the IKE Gateway and IPsec Crypto profile, but it does not have a direct PFS setting. PFS is defined within the IPsec Crypto profile. Enabling it at the tunnel level is not possible; you must configure it in the crypto profile.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.