PCNSE Secure Access and VPN Practice Question
A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?
⚠ Common exam trap
The trap here is assuming that configuring the IKE Crypto profile alone is sufficient for Phase 1, forgetting that authentication credentials like the pre-shared key must be explicitly set in the IKE Gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IKE Gateway configuration does not have the pre-shared key configured.
For a site-to-site VPN using pre-shared key authentication, the IKE Gateway must include the pre-shared key. Without it, IKE Phase 1 cannot authenticate the peer, and the tunnel will not establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not handle authentication. Therefore, the missing pre-shared key is the most likely cause of the failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The tunnel interface is not configured with an IP address.
Why it's wrong here
The tunnel interface IP address is required for routing traffic through the tunnel, but it does not affect IKE Phase 1 establishment. Without an IP address, the tunnel might come up but traffic would not route correctly. The failure here is in Phase 1, which occurs before the tunnel interface is used for data forwarding.
- ✗
The IKE Gateway is configured with the wrong local interface.
Why it's wrong here
If the local interface in the IKE Gateway is incorrect, the firewall might not send or receive IKE packets on the expected interface, causing Phase 1 to fail. However, the question specifies that the IKE Crypto profile is correctly configured and the failure is due to a missing component. A wrong local interface is a possible misconfiguration but is less directly tied to the described scenario than a missing pre-shared key.
- ✓
The IKE Gateway configuration does not have the pre-shared key configured.
Why this is correct
In a site-to-site VPN using pre-shared key authentication, the IKE Gateway must have the pre-shared key defined under the IKE Gateway configuration. Without it, the firewall cannot authenticate the peer during IKE Phase 1, and the tunnel will fail to establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not provide authentication credentials.
- ✗
The IPsec Crypto profile is missing an encryption algorithm.
Why it's wrong here
The IPsec Crypto profile defines the encryption and authentication algorithms for Phase 2, not Phase 1. The question states that IKE Phase 1 fails, so the IPsec Crypto profile is not yet relevant. Even if the IPsec Crypto profile were missing an algorithm, the failure would occur in Phase 2, not Phase 1.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.