PCNSE Troubleshoot Practice Question
Which THREE are required for a successful firewall-to-firewall IPSec VPN tunnel? (Choose three.)
⚠ Common exam trap
Many exam-takers assume hardware or CA compatibility is required, but the PCNSE exam tests that only IKE parameters, authentication credentials, and proxy IDs must match—not the firewall model or a shared CA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Matching IKE version and encryption algorithms
IKE (Internet Key Exchange) is the protocol that establishes the security association (SA) for an IPsec VPN. Both firewalls must agree on the IKE version (v1 or v2) and the encryption algorithms (e.g., AES-256, 3DES) during Phase 1 negotiation; a mismatch will cause the tunnel to fail to establish.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Matching IKE version and encryption algorithms
Why this is correct
These are phase 1 parameters that must match.
- ✗
Same firewall model
Why it's wrong here
Different models can form VPN tunnels.
- ✗
Same certificate authority
Why it's wrong here
Certificate-based authentication may use different CAs.
- ✓
Matching proxy IDs (local/remote subnets)
Why this is correct
Phase 2 selectors must match to establish IPsec SA.
- ✓
Matching pre-shared keys or certificates
Why this is correct
Authentication must use the same key or trusted certificates.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.