PCNSE Secure Access and VPN Practice Question
A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?
⚠ Common exam trap
Candidates often confuse the IKE Crypto profile with the IPsec Crypto profile, or thinking that PFS is configured at the gateway or tunnel level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the IPsec Crypto profile, set the DH Group to group14.
Perfect Forward Secrecy for IKE phase 2 is configured in the IPsec Crypto profile. The DH Group field in this profile specifies the Diffie-Hellman group used for PFS during phase 2. Setting it to group14 ensures that the IPsec SA uses PFS with group14. The IKE Crypto profile controls phase 1, while the IPsec Crypto profile controls phase 2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In the IKE Gateway configuration, enable 'Perfect Forward Secrecy' and select group14.
Why it's wrong here
There is no such setting in the IKE Gateway configuration. PFS is not configured at the gateway level; it is part of the crypto profiles. The IKE Gateway defines the peer address, authentication, and advanced options like NAT traversal, but not PFS.
- ✗
In the IKE Crypto profile, set the DH Group to group14.
Why it's wrong here
The IKE Crypto profile is used for IKE phase 1, not phase 2. Setting the DH group in the IKE Crypto profile affects the initial key exchange for IKE SA, but does not control PFS for the IPsec SA. PFS for phase 2 is configured in the IPsec Crypto profile.
- ✓
In the IPsec Crypto profile, set the DH Group to group14.
Why this is correct
The IPsec Crypto profile is used for IKE phase 2 and includes the DH Group setting for PFS. By setting the DH Group to group14 in the IPsec Crypto profile, the firewall will propose PFS with group14 during phase 2, ensuring that the IPsec SA uses PFS with the specified group.
- ✗
In the IPsec Tunnel configuration, enable 'Perfect Forward Secrecy' and select group14.
Why it's wrong here
The IPsec Tunnel configuration is where you bind the IKE Gateway and IPsec Crypto profile, but it does not have a direct PFS setting. PFS is defined within the IPsec Crypto profile. Enabling it at the tunnel level is not possible; you must configure it in the crypto profile.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.