Courseiva

CCNA Secure Access and VPN Questions

21 questions · Secure Access and VPN · All types, answers revealed

1
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between a Palo Alto Networks firewall and a third-party vendor's VPN gateway. The administrator wants to ensure that the IKE phase 2 (IPsec) SA is established with perfect forward secrecy (PFS) using Diffie-Hellman group 14. Which configuration on the Palo Alto Networks firewall is required to meet this requirement?

A.In the IKE Gateway configuration, enable 'Perfect Forward Secrecy' and select group14.
B.In the IKE Crypto profile, set the DH Group to group14.
C.In the IPsec Crypto profile, set the DH Group to group14.
D.In the IPsec Tunnel configuration, enable 'Perfect Forward Secrecy' and select group14.
AnswerC

The IPsec Crypto profile is used for IKE phase 2 and includes the DH Group setting for PFS. By setting the DH Group to group14 in the IPsec Crypto profile, the firewall will propose PFS with group14 during phase 2, ensuring that the IPsec SA uses PFS with the specified group.

Why this answer

Perfect Forward Secrecy for IKE phase 2 is configured in the IPsec Crypto profile. The DH Group field in this profile specifies the Diffie-Hellman group used for PFS during phase 2. Setting it to group14 ensures that the IPsec SA uses PFS with group14.

The IKE Crypto profile controls phase 1, while the IPsec Crypto profile controls phase 2.

Exam trap

The trap here is confusing the IKE Crypto profile with the IPsec Crypto profile, or thinking that PFS is configured at the gateway or tunnel level.

2
Multi-Selecthard

Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)

Select 3 answers
A.Dead peer detection interval
B.IKE encryption algorithm
C.IKE authentication algorithm
D.Local certificate
E.IKE version (v1 or v2)
AnswersB, C, E

IKE encryption algorithm must match because it secures Phase 1 negotiation itself; mismatched ciphers cause the peers to reject each other's proposals before any tunnel forms. This satisfies the stem's requirement that both peers agree on identical Phase 1 parameters for successful IPsec establishment.

Why this answer

Option B (IKE encryption algorithm) is correct because both peers must agree on the same Phase 1 encryption algorithm (e.g., AES-256) in their IKE proposals; a mismatch causes the ISAKMP/IKE SA negotiation to fail. Option C (IKE authentication algorithm) is correct because the Phase 1 integrity/hash algorithm (e.g., SHA-256) must match on both peers for the IKE SA to be established. Option E (IKE version v1 or v2) is correct because IKEv1 and IKEv2 are incompatible protocols; peers must run the same version to negotiate the tunnel.

Option A (dead peer detection interval) is not required to match, since DPD timers are locally significant and can differ between peers without preventing tunnel establishment. Option D (local certificate) is not required to match, because each peer presents its own identity credential; certificates need only be trusted/validated, not identical.

Exam trap

The trap here is that candidates often confuse 'factors that must match' with 'factors that can be different'—DPD intervals and certificate requirements are not mandatory for tunnel establishment, while IKE version, encryption, and authentication algorithms are non-negotiable.

3
MCQeasy

When configuring GlobalProtect with certificate authentication, a user reports that the client prompts for username and password even though the certificate is installed. What is the most likely cause?

A.The certificate is expired
B.The portal authentication profile requires both certificate and password
C.The client certificate does not match the username
D.The root CA certificate is not imported into the firewall
AnswerB

The portal authentication profile governs which credential factors the client must supply. If it is set to require both certificate and password, the client prompts for credentials even when a valid certificate is present. Removing the password requirement restores certificate-only authentication.

Why this answer

When a GlobalProtect portal authentication profile is configured to require both certificate and password, the client will prompt for username and password even if a valid certificate is present. This is because the authentication profile explicitly enforces multi-factor authentication, meaning the certificate alone is insufficient for portal authentication. The client must satisfy all configured authentication factors before proceeding.

Exam trap

The trap here is that candidates often assume a valid certificate alone should suffice for authentication, overlooking that the portal authentication profile can be configured to require additional factors like a password, which forces the client to prompt for credentials regardless of certificate validity.

How to eliminate wrong answers

Option A is wrong because an expired certificate would typically result in an authentication failure or error message, not a prompt for username and password; the client would reject the certificate outright. Option C is wrong because a certificate that does not match the username would cause a certificate validation failure or mismatch error, not a username/password prompt; the client would not fall back to credential-based authentication. Option D is wrong because if the root CA certificate is not imported into the firewall, the firewall cannot validate the client certificate, leading to a certificate validation failure, not a prompt for credentials; the connection would be rejected.

4
MCQhard

A network engineer is configuring a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party VPN peer. The engineer wants to ensure that the firewall can establish the tunnel even if the peer initiates the connection. Which configuration is required on the Palo Alto Networks firewall?

A.Configure the IKE gateway with a static peer IP address and enable 'Passive' mode.
B.Configure the IPsec tunnel with 'Auto Key' and enable 'Responder Only' mode.
C.Configure the IKE gateway with a dynamic peer IP address and enable 'Aggressive' mode.
D.Configure the IKE gateway with a static peer IP address and ensure that the pre-shared key and proposals match the peer.
AnswerD

For the firewall to establish a tunnel, the IKE gateway must be configured with the peer IP address (static or dynamic) and the correct pre-shared key and proposals. The firewall will respond to IKE requests from the peer if the gateway configuration matches. No special mode is required to accept peer-initiated connections; the firewall can initiate or respond by default.

Why this answer

In Palo Alto Networks, an IKE gateway configured with a static peer IP address and matching pre-shared key and proposals will accept IKE requests from that peer. The firewall does not require a special mode to respond to peer-initiated connections; it can act as both initiator and responder. The key is that the gateway configuration must match the peer's settings.

Exam trap

The trap here is thinking that a special mode like 'Passive' or 'Responder Only' is needed for the firewall to accept peer-initiated connections, when actually the standard gateway configuration suffices.

5
MCQhard

An administrator is configuring GlobalProtect with certificate authentication. The portal is configured to use a certificate profile that validates client certificates against a trusted CA. Users report that authentication fails with the error 'Certificate validation failed'. The administrator has verified that the client certificates are issued by the correct CA and are not expired. What is the most likely cause of the failure?

A.The certificate revocation list (CRL) is not configured in the certificate profile.
B.The certificate profile is not configured to allow the certificate's extended key usage (EKU) for client authentication.
C.The client certificate is not installed in the user's personal certificate store.
D.The GlobalProtect portal is not configured with the correct SSL/TLS service profile.
AnswerB

In a certificate profile, you must specify the EKU that the client certificate must contain, such as 'clientAuth'. If the profile does not permit the EKU present in the certificate, validation fails. The error 'Certificate validation failed' often indicates this mismatch, even if the certificate is otherwise valid and from a trusted CA.

Why this answer

Certificate validation in GlobalProtect checks multiple attributes, including EKU. If the certificate profile does not allow the EKU present in the client certificate, validation fails even if the certificate is from a trusted CA and not expired. The error message 'Certificate validation failed' is a strong indicator of such a mismatch.

Exam trap

The trap here is focusing on CA trust and expiration while overlooking the extended key usage requirement in the certificate profile.

6
MCQeasy

A company is deploying GlobalProtect for remote users. The security team wants to ensure that only users who authenticate successfully can access internal resources. They have configured the portal and gateway with an authentication profile that uses LDAP. However, users report that after authenticating, they can connect but cannot access any internal resources. What is the most likely cause?

A.The GlobalProtect portal is not configured to push the correct routes to the clients.
B.The GlobalProtect gateway is not configured with a certificate for SSL/TLS.
C.The security policy allowing traffic from the GlobalProtect zone to the internal zone is missing or misconfigured.
D.The LDAP authentication profile is not properly mapped to the GlobalProtect gateway.
AnswerC

After a user connects via GlobalProtect, traffic from the user is placed in a security zone (typically the GlobalProtect zone). A security policy must explicitly allow traffic from that zone to the internal resources. If the policy is missing or incorrect, the user can connect but cannot access resources. This is a common oversight.

Why this answer

In GlobalProtect, after a user connects, their traffic is subject to security policies. The GlobalProtect zone is typically used for incoming VPN traffic. A security policy must allow traffic from the GlobalProtect zone to the internal zone or resources.

Without this policy, the user can authenticate and establish a tunnel but cannot access internal resources.

Exam trap

The trap here is focusing on authentication or routing issues when the user can already connect, overlooking the need for a security policy to permit access to internal resources.

7
Drag & Dropmedium

Order the steps to capture traffic on a Palo Alto Networks firewall using the packet capture feature.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for packet capture on a Palo Alto Networks firewall is: first configure the capture filter to define which traffic to capture, then start the capture, generate the traffic, stop the capture to finalize the data, and finally download the capture file. This order ensures that the desired traffic is captured cleanly and the file is ready for analysis.

8
MCQeasy

A GlobalProtect user can successfully authenticate to the portal but cannot connect to the internal gateway. The portal and gateway are configured on the same firewall. What is the most likely cause?

A.User not assigned a license
B.Incorrect gateway IP address in portal configuration
C.Gateway interface not in the same zone as portal
D.Gateway MTU mismatch
AnswerB

The portal hands the client the gateway address to connect to; if that configured address is wrong, authentication succeeds but the tunnel to the internal gateway fails. This matches the stem's symptom of portal success with gateway failure on the same firewall.

Why this answer

When the portal and gateway are on the same firewall, the portal configuration must specify the correct IP address or FQDN for the gateway. If the gateway IP address in the portal configuration is incorrect, the client will successfully authenticate to the portal but then fail to establish a tunnel to the gateway because it cannot reach the gateway at the specified address. This is the most common cause of this symptom.

Exam trap

The trap here is that candidates often assume the issue is a zone mismatch or license problem, but the portal and gateway can be in different zones and licenses are not required for basic gateway connectivity, so the incorrect gateway IP address in the portal configuration is the precise cause.

How to eliminate wrong answers

Option A is wrong because license assignment is not required for GlobalProtect gateway connectivity; licenses are only needed for features like GlobalProtect subscription services or specific user counts, not for basic gateway authentication and tunnel setup. Option C is wrong because the portal and gateway can be in different zones; in fact, they are often placed in separate zones (e.g., portal in an untrust zone, gateway in a trust zone) and this does not prevent connectivity as long as inter-zone rules allow the traffic. Option D is wrong because an MTU mismatch would cause packet fragmentation issues or connectivity drops after the tunnel is established, not a failure to connect to the gateway after portal authentication.

9
MCQmedium

A network administrator is troubleshooting an IPsec site-to-site VPN that fails to establish. IKE phase 1 completes successfully, but phase 2 fails with a 'no proposal chosen' message. Both sides have identical IKE and IPsec crypto profiles, and the pre-shared key is correct. What is the most likely cause of the failure?

A.The proxy IDs (local/remote subnets) do not match between peers
B.The tunnel is configured as route-based instead of policy-based
C.The IKE gateway's local interface is down
D.Dead peer detection is not enabled on the IKE gateway
AnswerA

IKE phase 1 succeeding confirms peer authentication and proposal agreement. Phase 2 'no proposal chosen' with identical crypto profiles points to proxy ID mismatch, since the firewall selects the IPsec SA based on matching local and remote subnet selectors.

Why this answer

In IPsec site-to-site VPNs, IKE phase 1 establishes the secure management channel using parameters like encryption, authentication, and Diffie-Hellman groups. Phase 2 negotiates the IPsec security associations (SAs) for actual data traffic, and the 'no proposal chosen' error indicates a mismatch in the phase 2 parameters. Since both sides have identical crypto profiles and the pre-shared key is correct, the most likely cause is that the proxy IDs (local and remote subnets) do not match between peers.

Proxy IDs define the traffic selectors that each peer expects to protect; if they are misaligned, the IPsec SA negotiation fails even if all other settings are identical.

Exam trap

The trap here is that candidates often assume identical crypto profiles guarantee phase 2 success, overlooking that proxy IDs (traffic selectors) are a separate, critical parameter that must be mirrored exactly on both peers.

How to eliminate wrong answers

Option B is wrong because a route-based tunnel (using a tunnel interface) still requires matching proxy IDs or traffic selectors in the IPsec profile; the failure mode for proxy ID mismatch is the same regardless of tunnel type. Option C is wrong because if the IKE gateway's local interface were down, IKE phase 1 would not complete successfully, but the question states phase 1 completes. Option D is wrong because dead peer detection (DPD) is a keepalive mechanism for detecting peer availability and does not affect the negotiation of IPsec SAs or cause a 'no proposal chosen' error.

10
MCQmedium

An IPSec tunnel between two PA firewalls fails to establish. On the initiator, 'show vpn ipsec-sa' shows no SAs. Which debug command would provide the most detailed information about IKE negotiation?

A.show counter global | match ipsec
B.show log system
C.debug ike global on
D.debug flow basic
AnswerC

With no IPsec SAs present, the failure lies in Phase 1, so IKE negotiation must be examined. The 'debug ike global on' command enables global IKE daemon debugging, exposing payload exchanges, proposal mismatches and authentication failures that explain why the tunnel never reaches quick mode. This targets the negotiation stage the stem identifies as failing.

Why this answer

'debug ike global on' enables detailed IKE (Internet Key Exchange) debugging on Palo Alto firewalls, capturing Phase 1 and Phase 2 negotiation messages, including proposal mismatches, authentication failures, and timeout errors. Since no IPsec SAs exist, the issue lies in IKE negotiation, and this command provides the most granular, real-time output to diagnose why the tunnel fails to establish.

Exam trap

The trap here is that candidates often confuse 'debug flow basic' (data-plane) with IKE debugging (control-plane), or assume 'show counter global' will reveal negotiation failures, when in fact counters only track post-establishment statistics and not the IKE handshake itself.

How to eliminate wrong answers

Option A is wrong because 'show counter global | match ipsec' displays aggregate IPsec packet counters (e.g., encaps/decaps, drops) but does not provide IKE negotiation details; it is useful for post-establishment traffic issues, not for debugging why SAs are missing. Option B is wrong because 'show log system' shows system-level events (e.g., admin logins, config changes) but does not capture IKE-specific debug messages; it lacks the granularity needed for protocol-level negotiation failures. Option D is wrong because 'debug flow basic' is used for debugging data-plane packet flow (e.g., session setup, NAT, routing) and does not cover IKE control-plane negotiation; it would not reveal why IKE Phase 1 or Phase 2 fails.

11
MCQmedium

A network security engineer is configuring a route-based IPsec VPN between two Palo Alto Networks firewalls. The engineer needs to ensure that the tunnel interface is used for dynamic routing updates and that the VPN can fail over to a backup path if the primary path goes down. Which configuration is required to achieve this?

A.Use policy-based VPN with proxy IDs and configure multiple proxy IDs for redundancy.
B.Enable IKEv2 and configure a separate tunnel interface for each path, then use OSPF with equal-cost multipath.
C.Configure a tunnel interface, assign it to a zone, and enable tunnel monitoring with a destination IP address.
D.Enable IKEv1 with aggressive mode and configure multiple pre-shared keys for each path.
AnswerC

A tunnel interface is required for route-based VPN, and assigning it to a zone allows policy enforcement. Tunnel monitoring sends ICMP probes to a specified IP address; if probes fail, the tunnel is considered down, triggering failover via routing changes. This directly addresses the need for dynamic routing and failover.

Why this answer

A route-based VPN requires a tunnel interface to participate in dynamic routing. Tunnel monitoring detects when the primary path fails, allowing routing protocols to withdraw routes and use a backup path. This combination ensures both dynamic routing and failover, which are essential for the described requirements.

Exam trap

The trap here is assuming that dynamic routing protocols alone provide failover without tunnel monitoring, but they need a trigger to detect path failure.

12
MCQhard

A network security engineer is configuring a new site-to-site IPsec VPN between two Palo Alto Networks firewalls. The design requires that the IKE Phase 1 negotiation must be cryptographically protected and that the peer's identity is verified using a pre-shared key. The engineer configures an IKE Crypto profile with AES-256-CBC, SHA-256, and DH Group 14. After committing, the tunnel fails to establish. Which component is most likely missing or misconfigured to cause this failure?

A.The tunnel interface is not configured with an IP address.
B.The IKE Gateway is configured with the wrong local interface.
C.The IKE Gateway configuration does not have the pre-shared key configured.
D.The IPsec Crypto profile is missing an encryption algorithm.
AnswerC

In a site-to-site VPN using pre-shared key authentication, the IKE Gateway must have the pre-shared key defined under the IKE Gateway configuration. Without it, the firewall cannot authenticate the peer during IKE Phase 1, and the tunnel will fail to establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not provide authentication credentials.

Why this answer

For a site-to-site VPN using pre-shared key authentication, the IKE Gateway must include the pre-shared key. Without it, IKE Phase 1 cannot authenticate the peer, and the tunnel will not establish. The IKE Crypto profile only defines encryption and hashing algorithms; it does not handle authentication.

Therefore, the missing pre-shared key is the most likely cause of the failure.

Exam trap

The trap here is assuming that configuring the IKE Crypto profile alone is sufficient for Phase 1, forgetting that authentication credentials like the pre-shared key must be explicitly set in the IKE Gateway.

13
MCQeasy

Refer to the exhibit. A network engineer sees multiple IKE SAs for the same peer. What does this indicate?

A.A configuration error causes duplicate SAs.
B.Multiple Phase 2 tunnels are established.
C.Multiple Phase 1 proposals are accepted.
D.The firewall is under DDoS attack.
AnswerA

Correct. Multiple IKE SAs for the same peer indicate a configuration error, such as duplicate IKE gateways. When two or more IKE gateways are configured with identical peer IP settings, each gateway establishes its own IKE SA, resulting in multiple SAs.

Why this answer

In Palo Alto firewalls, each IKE gateway configuration establishes a separate IKE SA. If multiple IKE gateways are configured with the same peer IP address (e.g., duplicated or misconfigured gateways), multiple IKE SAs will appear for that peer. This typically indicates a configuration error rather than an intentional design, as each peer should usually have a single IKE gateway.

Multiple Phase 2 tunnels under the same IKE gateway do not create additional IKE SAs; they only create additional Phase 2 SAs within the same IKE SA. Therefore, multiple IKE SAs for the same peer point to duplicate or erroneous IKE gateway configurations.

Exam trap

A common misconception is that multiple IKE SAs for the same peer always indicate multiple Phase 2 tunnels. In reality, Phase 2 tunnels do not create extra IKE SAs. Instead, multiple IKE SAs are caused by multiple IKE gateway configurations for the same peer, which is often a configuration error.

How to eliminate wrong answers

Option A is wrong because duplicate IKE SAs are not a configuration error; they are a normal result of multiple Phase 2 tunnels. Option C is wrong because multiple Phase 1 proposals are negotiated during a single IKE SA establishment, not resulting in separate IKE SAs; only one proposal is selected per IKE SA. Option D is wrong because a DDoS attack would typically cause a flood of half-open or invalid SAs, not multiple established IKE SAs for the same peer with valid Phase 2 tunnels.

14
MCQmedium

An organization uses GlobalProtect with multiple gateways for different regions. Users in the Asia region are connecting to the wrong gateway. What is the most likely cause?

A.Users are manually selecting the wrong gateway from the client.
B.The gateways are not configured with priority settings.
C.The gateway selection rules on the portal do not match the users' source IP ranges.
D.The DNS resolution for the portal returns multiple IPs in round-robin.
AnswerC

Gateway selection rules on the portal map source IP ranges to preferred gateways, so mismatched ranges send Asian users to the wrong region. The portal agent config evaluates these rules before the client connects, making the source-IP match the deciding factor here.

Why this answer

GlobalProtect gateway selection is primarily determined by the gateway selection rules configured on the portal. These rules evaluate the user's source IP address against defined IP ranges (or countries) to assign the appropriate gateway. If the rules do not match the users' source IP ranges in the Asia region, the portal will either fail to assign a gateway or assign a default gateway, causing users to connect to the wrong gateway.

Exam trap

The trap here is that candidates often confuse gateway priority (which controls load balancing within a region) with gateway selection rules (which control which region's gateway a user connects to), leading them to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because while manual selection is possible, the scenario describes users 'connecting to the wrong gateway,' which implies an automated selection failure, not user error; manual selection would require deliberate action and is not the 'most likely cause' in a multi-region deployment. Option B is wrong because priority settings on gateways control load balancing and failover order among gateways within the same region, not which region a user connects to; gateway selection is based on portal rules, not gateway priority. Option D is wrong because DNS round-robin for the portal would distribute users across multiple portal IPs, but the portal itself still enforces gateway selection rules; this would not cause users to connect to the wrong gateway unless the portal configuration is incorrect.

15
Multi-Selectmedium

Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?

Select 3 answers
A.Verify the routing table on both firewalls.
B.Check the firewall policies for the tunnel zone.
C.Increase the IPSec SA lifetime.
D.Verify the proxy IDs on both peers match.
E.Ensure the tunnel interface is placed in a virtual router.
AnswersA, B, D

A tunnel can be up while traffic fails because no route directs packets into the VPN. Verifying the routing table on both firewalls confirms that remote subnet routes point to the tunnel interface, satisfying the stem's requirement.

Why this answer

Option A is correct because when a site-to-site VPN tunnel is up but traffic does not pass, the most common cause is a missing or incorrect route on one or both firewalls; verifying the routing table ensures that traffic destined for the remote subnet is directed into the tunnel interface rather than out a default or wrong interface. Option B is correct because firewall policies (security rules) must explicitly permit traffic between the local and remote tunnel zones; even with a healthy IPSec SA, an implicit deny or missing allow rule for the tunnel zone will silently drop packets. Option D is correct because proxy IDs (traffic selectors) define which source/destination subnets are permitted through the tunnel, and if the local and remote peers have mismatched proxy IDs, Phase 2 may appear up while traffic for the actual subnets is dropped or not encrypted.

Option C is not correct because increasing the IPSec SA lifetime only affects how often keys are renegotiated and does not resolve a no-traffic condition when the tunnel is already established. Option E is not correct because placing the tunnel interface in a virtual router is a design/configuration choice, not a troubleshooting step, and a tunnel can pass traffic without being bound to a virtual router.

Exam trap

The trap here is that candidates assume a tunnel being 'up' guarantees traffic flow, but the PCNSE exam tests that you must separately verify routing, security policies, and proxy IDs—each of which can block traffic independently of the tunnel's control-plane state.

16
MCQmedium

An organization has two sites connected via IPSec VPN. The tunnel is up, but ICMP traffic between sites fails. No other traffic works. The firewall policy allows any-any. What is the most likely issue?

A.The IKE phase 1 proposal is mismatched.
B.The proxy IDs (interesting traffic) are not configured correctly.
C.The IPSec crypto profile uses AES-256 and the peer uses 3DES.
D.The tunnel interface MTU is set too low.
AnswerB

With route-based or policy-based tunnels, mismatched proxy IDs mean phase 2 selectors never match, so the firewall drops traffic even though IKE is up. Correctly aligned local and remote proxy IDs restore ICMP and all other traffic.

Why this answer

When the IPSec tunnel is up but no traffic passes, the most common cause is misconfigured proxy IDs (also called interesting traffic selectors). Proxy IDs define which source/destination subnets are permitted through the tunnel; if they don't match on both peers, the tunnel may establish (IKE and IPsec SAs are created) but the firewall will not encrypt or forward traffic because it does not match the defined selectors. Since the firewall policy allows any-any, the issue is not a policy block, pointing directly to proxy ID mismatch.

Exam trap

The trap here is that candidates assume a tunnel being 'up' means all traffic should work, but in Palo Alto Networks, the tunnel state only reflects IKE and IPsec SA establishment, not the correctness of proxy IDs which control traffic selection.

How to eliminate wrong answers

Option A is wrong because an IKE phase 1 proposal mismatch would prevent the tunnel from coming up at all—the tunnel being up indicates phase 1 completed successfully. Option C is wrong because an IPSec crypto profile mismatch (e.g., AES-256 vs 3DES) would cause the tunnel to fail during phase 2 negotiation, not allow the tunnel to be up with no traffic. Option D is wrong because a low tunnel interface MTU would cause fragmentation or packet drops for large packets, but ICMP traffic (typically small packets) would still pass; it would not cause a complete failure of all traffic.

17
MCQeasy

A security engineer is setting up a route-based IPsec VPN between a Palo Alto Networks firewall and a third-party peer. The engineer has configured the IKE gateway, IPsec crypto profile, and tunnel interface. The tunnel is established, but traffic is not passing. The engineer checks the routing table and sees that routes for the remote subnet are pointing to the tunnel interface. What is the next logical step to troubleshoot the issue?

A.Confirm that the proxy IDs are correctly configured on both peers.
B.Verify that the IPsec crypto profile uses the same encryption algorithm as the peer.
C.Check the IKE Phase 1 and Phase 2 status to ensure the tunnel is fully established.
D.Verify that the security policy allows traffic from the tunnel zone to the internal zone.
AnswerD

In a route-based VPN, traffic entering the tunnel interface is associated with a security zone. A security policy must permit traffic from the tunnel zone to the destination zone. If the policy is missing or incorrect, traffic will be dropped even though the tunnel is up and routes are correct. Checking the security policy is a fundamental troubleshooting step.

Why this answer

When a route-based VPN tunnel is up and routes are correct, the next troubleshooting step is to check security policies. Traffic entering the tunnel interface is subject to security policy rules based on the tunnel zone. If no rule permits the traffic, it will be dropped.

Other options like rechecking tunnel status or crypto profiles are unnecessary because the tunnel is already established.

Exam trap

The trap here is continuing to focus on VPN tunnel parameters such as proxy IDs or crypto profiles, even though the tunnel is already up, instead of moving to policy and routing checks that affect traffic flow.

18
MCQeasy

A company is deploying GlobalProtect for remote users and wants to enforce that only users with valid certificates are allowed to connect. Which configuration is required on the GlobalProtect gateway?

A.Define a tunnel interface with an IP address that matches the certificate subject
B.Set the gateway's IP pool to require certificate authentication
C.Configure a certificate profile in the gateway's authentication settings
D.Configure client authentication in the portal with a certificate profile
AnswerC

A certificate profile bound to the gateway's authentication settings makes the firewall validate the client certificate chain against the specified trusted CA, rejecting connections without a valid certificate. This enforces certificate-based authentication for GlobalProtect remote users.

Why this answer

A certificate profile must be configured in the gateway's authentication settings to enforce certificate-based authentication. This profile defines the trusted Certificate Authority (CA) and validation criteria (e.g., CRL checking, OCSP), ensuring only clients presenting a valid certificate issued by that CA can establish a GlobalProtect tunnel. Without this, the gateway would fall back to username/password or other configured authentication methods.

Exam trap

The trap here is that candidates often confuse portal authentication settings with gateway authentication settings, assuming that configuring a certificate profile on the portal will automatically enforce certificate-based access on the gateway, but the gateway requires its own separate authentication configuration.

How to eliminate wrong answers

Option A is wrong because a tunnel interface IP address does not need to match the certificate subject; the certificate subject is used for identity mapping, not for IP assignment. Option B is wrong because the IP pool is used for assigning client IP addresses from a defined range, not for requiring certificate authentication; certificate enforcement is handled separately in the authentication profile. Option D is wrong because client authentication in the portal controls web-based access to the portal interface, not the gateway tunnel; gateway authentication settings are independent and must be configured directly on the gateway.

19
Multi-Selecteasy

Which TWO of the following are supported authentication methods for IPSec VPN tunnel setup between two Palo Alto Networks firewalls?

Select 2 answers
A.Certificate
B.RADIUS
C.SAML
D.LDAP
E.Pre-shared key
AnswersA, E

Certificate-based authentication is supported for IPSec VPN tunnels between Palo Alto Networks firewalls, using X.509 certificates exchanged during IKE to authenticate peers. This satisfies the scenario's requirement for a supported method, since both firewalls can validate each other's identity via a trusted certificate authority rather than pre-shared keys.

Why this answer

Option A (Certificate) is correct because Palo Alto Networks firewalls support certificate-based authentication for IPSec VPN IKE peers, where each firewall presents an X.509 certificate and validates the peer's certificate against a trusted CA profile during IKE Phase 1. Option E (Pre-shared key) is correct because PSK authentication is a native, commonly used IKE Phase 1 authentication method for site-to-site IPSec tunnels between Palo Alto firewalls, configured under the IKE Gateway's authentication settings. Options B (RADIUS), C (SAML), and D (LDAP) are not valid IKE peer authentication methods for IPSec tunnel establishment; these are user authentication mechanisms used for GlobalProtect, administrative access, or User-ID, and they operate at the application/user layer rather than authenticating the IKE gateway peer itself.

Exam trap

The trap here is that candidates confuse user authentication methods (RADIUS, SAML, LDAP) with device-to-device IPsec tunnel authentication, which only supports pre-shared keys and certificates on Palo Alto firewalls.

20
MCQhard

Refer to the exhibit. A site-to-site VPN is configured between two branches. The tunnel is up but traffic is not passing. What is the most likely issue?

A.The IKE gateway is not configured with the correct peer IP.
B.No security policy allows traffic from the VPN zone.
C.The proxy IDs do not match the remote peer.
D.The tunnel interface is not assigned to a zone.
AnswerB

A tunnel can negotiate successfully at IKE and IPsec phases while user traffic is silently dropped if no security policy permits the VPN zone as source or destination, which is the classic cause of an up-but-passing-no-traffic state.

Why this answer

When a site-to-site VPN tunnel is up but traffic is not passing, the most common cause is the absence of a security policy that permits traffic from the VPN zone to the destination zone. Even if IKE and IPsec SAs are established, the firewall drops the decrypted traffic if no rule explicitly allows it. This is a fundamental Palo Alto Networks concept: tunnel establishment and data forwarding are separate control and data plane functions.

Exam trap

Palo Alto Networks often tests the misconception that a tunnel being up automatically means traffic will pass, but Palo Alto Networks requires an explicit security policy to permit decrypted traffic from the VPN zone.

How to eliminate wrong answers

Option A is wrong because if the IKE gateway had an incorrect peer IP, the tunnel would not come up at all (IKE phase 1 would fail). Option C is wrong because mismatched proxy IDs would cause IPsec SA negotiation to fail, preventing the tunnel from reaching an up state. Option D is wrong because a tunnel interface not assigned to a zone would cause the interface itself to be inactive, and the tunnel would not show as up; the question states the tunnel is up, so the interface must be zoned.

21
Multi-Selecthard

Which THREE of the following are capabilities of GlobalProtect Host Information Profile (HIP)?

Select 3 answers
A.Check the user's location
B.Check the browser version
C.Check if antivirus is installed and running
D.Check if disk encryption is enabled
E.Check the operating system version
AnswersC, D, E

HIP collects host posture data via the GlobalProtect agent, including whether antivirus software is installed and actively running. This satisfies the stem's requirement by confirming endpoint security compliance before granting or restricting access through a HIP-enabled security policy.

Why this answer

Option C is correct because HIP collects host data on endpoint security software, including whether antivirus/anti-malware is installed, running, and up to date, which is a core HIP check. Option D is correct because HIP can verify disk encryption status (for example, BitLocker or FileVault) as part of its endpoint compliance data. Option E is correct because HIP reports the operating system version and patch level, allowing security policies to require a minimum OS version.

Option A is not a HIP capability because HIP profiles endpoint host attributes, not the user's geographic location, which is handled by other means such as source region or GlobalProtect gateway selection. Option B is not a HIP capability because HIP does not natively report browser version; browser checks are not part of the standard HIP object categories.

Exam trap

The trap here is that candidates often confuse HIP with GlobalProtect's location-based features or application-level checks, assuming HIP can verify user location or browser versions, when in reality HIP is strictly focused on endpoint security posture attributes like OS, antivirus, disk encryption, and patch management.

Ready to test yourself?

Try a timed practice session using only Secure Access and VPN questions.