PCNSE · domain
Secure Access and VPN
Secure Access and VPN covers IPsec site-to-site tunnels, GlobalProtect gateway and portal configuration, and SSL/IPsec remote access on PAN-OS. Questions are scenario-based: you diagnose IKE or IPsec failures from CLI output, choose the right debug or packet capture, and reason about gateway selection, routing, and proxy IDs.
Focused practice
Practice Secure Access and VPN questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Secure Access and VPN
Be able to read IKE and IPsec CLI output, run the right debug to isolate a failed tunnel, and configure GlobalProtect gateway selection and packet capture correctly. The single most important thing: match phase 2 proxy-IDs and proposals exactly on both peers.
Watch out for
Common Secure Access and VPN exam traps
- ▸Assuming phase 2 'no proposal chosen' is a PSK or peer problem when it is usually a mismatched proxy-ID, encryption, or hash setting.
- ▸Forgetting that GlobalProtect gateway selection depends on source region, priority, and agent config, not just geographic proximity.
- ▸Running packet capture without setting the correct stage or filter, so the captured traffic never shows the failing IKE or ESP packets.
Question index
All Secure Access and VPN questions (21)
Click any question to see the full explanation, or start a practice session above.
A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?
Medium2Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)
Hard3When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?
Easy4A network engineer is configuring a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party VPN peer. The engineer wants to ensure that the firewall can establish the tunnel even if the peer initiates the connection. Which configuration is required on the Palo Alto Networks firewall?
Hard5An administrator is configuring GlobalProtect with certificate authentication. The portal is configured to use a certificate profile that validates client certificates against a trusted CA. Users report that authentication fails with the error 'Certificate validation failed'. The administrator has verified that the client certificates are issued by the correct CA and are not expired. What is the most likely cause of the failure?
Hard6A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?
Easy7Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.
Medium8A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?
Easy9A network administrator is troubleshooting an IPsec site-to-site VPN that fails to establish. IKE phase 1 completes successfully, but phase 2 fails with a 'no proposal chosen' message. Both sides have identical IKE and IPsec crypto profiles, and the pre-shared key is correct. What is the most likely cause of the failure?
Medium10An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?
Medium11A network security engineer is configuring a route-based IPsec VPN between two Palo Alto Networks firewalls. The engineer needs to ensure that the tunnel interface is used for dynamic routing updates and that the VPN can fail over to a backup path if the primary path goes down. Which configuration is required to achieve this?
Medium12A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?
Hard13Refer to the exhibit. A network engineer sees multiple IKE SAs for the same peer. What does this indicate?
Easy14An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?
Medium15Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?
Medium16An organization has two sites connected via IPSec VPN. The tunnel is up, but ICMP traffic between sites fails. No other traffic works. The firewall policy allows any-any. What is the most likely issue?
Medium17A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?
Easy18A company is deploying GlobalProtect for remote users and wants to enforce that only users with valid certificates are allowed to connect. Which configuration is required on the GlobalProtect gateway?
Easy19Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?
Easy20Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?
Hard21Which THREE of the following are capabilities of GlobalProtect Host Information Profile (HIP)?
HardOther domains
All PCNSE exam domains
Frequently asked questions
- What does the Secure Access and VPN domain cover on the PCNSE exam?
- Be able to read IKE and IPsec CLI output, run the right debug to isolate a failed tunnel, and configure GlobalProtect gateway selection and packet capture correctly. The single most important thing: match phase 2 proxy-IDs and proposals exactly on both peers.
- How many questions are in this domain?
- This page lists all 21 Secure Access and VPN questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Access and VPN questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.