Courseiva
Secure Access and VPN →easyMultiple Choice

PCNSE Secure Access and VPN Practice Question

A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?

⚠ Common exam trap

The trap here is continuing to focus on VPN tunnel parameters such as proxy IDs or crypto profiles, even though the tunnel is already up, instead of moving to policy and routing checks that affect traffic flow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the security policy allows traffic from the tunnel zone to the internal zone.

When a route-based VPN tunnel is up and routes are correct, the next troubleshooting step is to check security policies. Traffic entering the tunnel interface is subject to security policy rules based on the tunnel zone. If no rule permits the traffic, it will be dropped. Other options like rechecking tunnel status or crypto profiles are unnecessary because the tunnel is already established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confirm that the proxy IDs are correctly configured on both peers.

    Why it's wrong here

    Proxy IDs are used during IPsec SA negotiation to define interesting traffic. If they were mismatched, the tunnel would likely fail to establish or only certain subnets would fail. Since the tunnel is up and routes are in place, proxy IDs are not the immediate concern for traffic not passing. Security policy is a more likely culprit.

  • ✗

    Verify that the IPsec crypto profile uses the same encryption algorithm as the peer.

    Why it's wrong here

    The IPsec crypto profile mismatch would prevent the tunnel from establishing in the first place. Since the tunnel is already up, the crypto profiles are compatible. The problem is not with the tunnel parameters but with the policy or routing that governs traffic flow through the established tunnel.

  • ✗

    Check the IKE Phase 1 and Phase 2 status to ensure the tunnel is fully established.

    Why it's wrong here

    The scenario states that the tunnel is established, so IKE and IPsec SAs are already up. Rechecking Phase 1 and Phase 2 status would not reveal why traffic is not passing. The issue is likely at a higher layer, such as security policy or routing, not in the tunnel establishment itself.

  • ✓

    Verify that the security policy allows traffic from the tunnel zone to the internal zone.

    Why this is correct

    In a route-based VPN, traffic entering the tunnel interface is associated with a security zone. A security policy must permit traffic from the tunnel zone to the destination zone. If the policy is missing or incorrect, traffic will be dropped even though the tunnel is up and routes are correct. Checking the security policy is a fundamental troubleshooting step.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.